CVE-2026-49986 - Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
Brief
CVE ID : CVE-2026-49986
Published : Aug. 14, 2026, 4:21 p. m.
- 44 minutes ago
Description : The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.
- 1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout.
When the `open_visualization` tool is invoked, `_find_dev_source()` resolves the user's active project directory as a candidate Cortex source root. The only validation performed by `_is_cortex_root()` is a check for the presence of an `mcp_server/` subdirectory and a `ui/unified-viz. html` file.
An attacker who places these two marker files in a malicious repository can cause Cortex to execute an arbitrary `mcp_server/server/visualize_bootstrap. py` from that directory via `subprocess. run([sys. executable, ...
