What is CVE-2026-49986?
CVE-2026-49986 affects the 'neuro-cortex-memory' MCP server, where the 'CLAUDE_PROJECT_DIR' environment variable is treated as a trusted developer checkout path. This flaw impacts versions prior to 3.17.1, potentially enabling unauthorized code execution. Immediate update to version 3.17.1 or later is recommended.
Azərbaycanca: CVE-2026-49986 'neuro-cortex-memory' MCP serverində aşkarlanıb, burada 'CLAUDE_PROJECT_DIR' mühit dəyişəni etibarlı developer yolu kimi qəbul edilir. Bu zəiflik 3.17.1 versiyasından əvvəlki versiyalara təsir edir, səlahiyyətsiz kod icrasına səbəb ola bilər. Serveri dərhal 3.17.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which product does CVE-2026-49986 affect?
CVE-2026-49986 affects the 'neuro-cortex-memory' MCP server.
To which version should I upgrade to fix this vulnerability?
It is recommended to immediately update the server to version 3.17.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.