CVE-2026-14611

MEDIUM

DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resource

Title source: cna
STIX 2.1

Description

A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of the file src/managers/MemoryManager.ts of the component Per-Project Auto-Memory Handler. Such manipulation of the argument workspacePath leads to exposure of resource. The attack may be performed from remote. Upgrading to version 0.4.0 is sufficient to fix this issue. The name of the patch is 6d709229b5199f6769fb3cf763e5122dcc43c079. It is advisable to upgrade the affected component.

References (8)

Core 8
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-376119 | DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resource
https://vuldb.com/vuln/376119
Signature, Permissions Required signature permissions-required
VDB-376119 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/376119/cti
Third Party Advisory third-party-advisory
CVE-2026-14611 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-14611
Third Party Advisory third-party-advisory
Submit #844651 | DeepMyst Mysti 0.4.0 Information Exposure / Improper Isolation
https://vuldb.com/submit/844651
Issue Tracking issue-tracking
https://github.com/DeepMyst/Mysti/issues/46
Patch issue-tracking patch
https://github.com/DeepMyst/Mysti/pull/49

Scores

CVSS v3 4.3
EPSS 0.0025
EPSS Percentile 16.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-668
Status published
Products (4)
DeepMyst/Mysti 0.1
DeepMyst/Mysti 0.2
DeepMyst/Mysti 0.3
DeepMyst/Mysti 0.4.0 (2 CPE variants)
Published Jul 03, 2026
Tracked Since Jul 04, 2026