CVE-2026-49986
7.1cdeust · Cortex
The Cortex MCP server (neuro-cortex-memory) prior to version 3.17.1 is vulnerable to the inclusion of functionality from an untrusted control sphere.
Executive summary
A security vulnerability in the Cortex MCP server allows local authenticated users to trigger unauthorized functionality, potentially leading to full system compromise.
Vulnerability
The software suffers from an inclusion of functionality from an untrusted control sphere (CWE-829). An authenticated local attacker can leverage this flaw to execute arbitrary code or manipulate memory, as the application fails to properly validate the source of included functions.
Business impact
With a CVSS score of 7.1, this vulnerability presents a high risk to environments where the Cortex MCP server is deployed. Successful exploitation by a local attacker could lead to complete system compromise, including the unauthorized modification or exfiltration of sensitive persistent memory data.
Remediation
Immediate Action: Update the neuro-cortex-memory package to version 3.18.0 or later as specified by the vendor's security advisory.
Proactive Monitoring: Review system and application logs for suspicious local process execution patterns or unexpected calls to memory management functions.
Compensating Controls: Apply strict local access controls and ensure that the principle of least privilege is enforced for all users who have access to the host operating system.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
The vulnerability is severe due to the potential for full system compromise. Administrators should immediately update the affected library to the fixed version to neutralize the risk of unauthorized functionality execution.