Junglewise Threat Intelligence

CVE-2026-49986: Cortex neuro-cortex-memory arbitrary code execution via CLAUDE_PROJECT_DIR

CVE-2026-49986 · Severity: high · CVSS 4 · Published 2026-07-01

Vendors: PyPI.

Executive brief

Cortex, a tool used for data visualization and memory management in AI development environments, contains a security flaw that allows for unauthorized code execution. If a user opens a malicious project directory in their development environment and triggers a visualization command, the software may automatically execute hidden malicious scripts. This could allow an attacker to steal sensitive files, credentials, or take full control of the user's local computer.

Technical details

The Cortex MCP server (neuro-cortex-memory) incorrectly trusts the 'CLAUDE_PROJECT_DIR' environment variable as a valid source root for developer tools. The '_find_dev_source' function in 'mcp_server/handlers/open_visualization.py' identifies candidate directories based on this variable, but only performs trivial validation by checking for the existence of an 'mcp_server/' directory and a 'ui/unified-viz.html' file. An attacker can craft a malicious repository containing these markers and a 'visualize_bootstrap.py' script. When a victim opens this directory in an IDE like Claude Code and invokes the 'open_visualization' tool, Cortex executes the attacker's Python script via 'subprocess.run' with the privileges of the local user. A secondary path in 'http_launcher.py' also allows for file overwrites via rsync. The vulnerability is addressed in version 3.18.0.

Affected products

  • cdeust neuro-cortex-memory <= 3.17.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: patched: Version 3.18.0 released
  • 2026-07-01: advisory

References