What is CVE-2026-19327?
A path traversal vulnerability has been discovered in the `getEnrichedData/enrichSession` function within `src/services/enricher.ts` of abracadabra50 claude-sesh 1.0.0. By manipulating the `sessionId` argument, a local attacker could gain unauthorized access to the file system; users are advised to apply the provided patch labeled '7'.
Azərbaycanca: abracadabra50 claude-sesh 1.0.0 məhsulunda `src/services/enricher.ts` faylındakı `getEnrichedData/enrichSession` funksiyasında `sessionId` arqumentinin manipulyasiyası nəticəsində yerli şəbəkədə path traversal zəifliyi aşkarlanıb. Bu, təcavüzkara fayl sistemində icazəsiz giriş imkanı verə bilər; istifadəçilərə təqdim olunan "7" nömrəli patchi tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which product and version is affected by CVE-2026-19327?
The vulnerability affects version 1.0.0 of abracadabra50 claude-sesh.
What is the recommended action to remediate CVE-2026-19327?
Users are advised to apply the provided patch labeled '7'.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.