CVE-2026-14611 Details
Description
A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of the file src/managers/MemoryManager.ts of the component Per-Project Auto-Memory Handler. Such manipulation of the argument workspacePath leads to exposure of resource. The attack may be performed from remote. Upgrading to version 0.4.0 is sufficient to fix this issue. The name of the patch is 6d709229b5199f6769fb3cf763e5122dcc43c079. It is advisable to upgrade the affected component.
A vulnerability in DeepMyst Mysti versions prior to 0.4.0 allows for the unauthorized exposure of project memory. This issue arises in the Per-Project Auto-Memory Handler component, specifically within the initProjectMemory function of MemoryManager.ts. The vulnerability can be exploited remotely by manipulating the workspacePath argument, leading to the unintended sharing of memory resources between different projects.
Users are advised to upgrade to DeepMyst Mysti version 0.4.0, which addresses this vulnerability by implementing a new project memory key schema that canonicalizes workspace paths and includes application-level user identities. Instructions for updating can be found in the project's GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 3, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DeepMyst/Mysti/ | [email protected] | Vendor |
| https://github.com/DeepMyst/Mysti/commit/6d709229b5199f6769fb3cf763e5122dcc43c079 | [email protected] | Source CodeVendor |
| https://github.com/DeepMyst/Mysti/issues/46 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/DeepMyst/Mysti/pull/49 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-14611 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/844651 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/376119 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/376119/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-668 | Exposure of Resource to Wrong Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DeepMyst Mysti | <bce0d2ba7904c056c576cf94db817635421d1f41> |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 3, 2026 | New CVE Received | [email protected] |
Volerion