CVE-2026-14611
MEDIUMDeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resource
Title source: cnaDescription
A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of the file src/managers/MemoryManager.ts of the component Per-Project Auto-Memory Handler. Such manipulation of the argument workspacePath leads to exposure of resource. The attack may be performed from remote. Upgrading to version 0.4.0 is sufficient to fix this issue. The name of the patch is 6d709229b5199f6769fb3cf763e5122dcc43c079. It is advisable to upgrade the affected component.
References (8)
Core 8
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-376119 | DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resource
https://vuldb.com/vuln/376119
Signature, Permissions Required signature
permissions-required
VDB-376119 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/376119/cti
Third Party Advisory third-party-advisory
CVE-2026-14611 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-14611
Third Party Advisory third-party-advisory
Submit #844651 | DeepMyst Mysti 0.4.0 Information Exposure / Improper Isolation
https://vuldb.com/submit/844651
Issue Tracking issue-tracking
https://github.com/DeepMyst/Mysti/issues/46
Patch issue-tracking
patch
https://github.com/DeepMyst/Mysti/pull/49
Product product
https://github.com/DeepMyst/Mysti/
Scores
CVSS v3
4.3
EPSS
0.0025
EPSS Percentile
16.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
CWE-668
Status
published
Products (4)
DeepMyst/Mysti
0.1
DeepMyst/Mysti
0.2
DeepMyst/Mysti
0.3
DeepMyst/Mysti
0.4.0 (2 CPE variants)
Published
Jul 03, 2026
Tracked Since
Jul 04, 2026