CVE-2026-49986: CWE-829: Inclusion of Functionality from Untrusted Control Sphere in cdeust Cortex
The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is invoked, `_find_dev_source()` resolves the user's active project directory as a candidate Cortex source root. The only validation performed by `_is_cortex_root()` is a check for the presence of an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places these two marker files in a malicious repository can cause Cortex to execute an arbitrary `mcp_server/server/visualize_bootstrap.py` from that directory via `subprocess.run([sys.executable, ...])`, achieving code execution with the privileges of the victim's local user process. Version 3.17.1 fixes the issue.
AI Analysis
Technical Summary
The Cortex MCP server (neuro-cortex-memory) before version 3.17.1 trusts the CLAUDE_PROJECT_DIR environment variable, set by Claude Code to the current project directory, as a valid Cortex developer checkout. When the open_visualization tool runs, it uses _find_dev_source() to resolve this directory as a Cortex source root based only on the presence of an mcp_server/ subdirectory and a ui/unified-viz.html file. An attacker can exploit this by placing these marker files in a malicious repository, causing Cortex to execute an arbitrary Python script (mcp_server/server/visualize_bootstrap.py) from that directory via subprocess.run with the victim's user privileges, resulting in code execution. Version 3.17.1 addresses this vulnerability.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the local user running the Cortex MCP server. This can lead to unauthorized actions and compromise of the affected system. The vulnerability requires local access or the ability to influence the CLAUDE_PROJECT_DIR environment variable and place files in the targeted directory.
Mitigation Recommendations
Version 3.17.1 of Cortex fixes this vulnerability. Users should upgrade to version 3.17.1 or later to remediate the issue. No official remediation level or temporary fix is provided. Until patched, users should avoid running the open_visualization tool with untrusted project directories set in CLAUDE_PROJECT_DIR.
CVE-2026-49986: CWE-829: Inclusion of Functionality from Untrusted Control Sphere in cdeust Cortex
Description
The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is invoked, `_find_dev_source()` resolves the user's active project directory as a candidate Cortex source root. The only validation performed by `_is_cortex_root()` is a check for the presence of an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places these two marker files in a malicious repository can cause Cortex to execute an arbitrary `mcp_server/server/visualize_bootstrap.py` from that directory via `subprocess.run([sys.executable, ...])`, achieving code execution with the privileges of the victim's local user process. Version 3.17.1 fixes the issue.
CVSS v4.0
Score 7.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Cortex MCP server (neuro-cortex-memory) before version 3.17.1 trusts the CLAUDE_PROJECT_DIR environment variable, set by Claude Code to the current project directory, as a valid Cortex developer checkout. When the open_visualization tool runs, it uses _find_dev_source() to resolve this directory as a Cortex source root based only on the presence of an mcp_server/ subdirectory and a ui/unified-viz.html file. An attacker can exploit this by placing these marker files in a malicious repository, causing Cortex to execute an arbitrary Python script (mcp_server/server/visualize_bootstrap.py) from that directory via subprocess.run with the victim's user privileges, resulting in code execution. Version 3.17.1 addresses this vulnerability.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the local user running the Cortex MCP server. This can lead to unauthorized actions and compromise of the affected system. The vulnerability requires local access or the ability to influence the CLAUDE_PROJECT_DIR environment variable and place files in the targeted directory.
Mitigation Recommendations
Version 3.17.1 of Cortex fixes this vulnerability. Users should upgrade to version 3.17.1 or later to remediate the issue. No official remediation level or temporary fix is provided. Until patched, users should avoid running the open_visualization tool with untrusted project directories set in CLAUDE_PROJECT_DIR.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-02T18:30:51.282Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7f457cbf8831d539681543
Added to database: 08/14/2026, 16:42:36 UTC
Last enriched: 08/22/2026, 13:15:17 UTC
Last updated: 09/08/2026, 22:52:13 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.