{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/consciousness-explorer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["consciousness-explorer","sublinear-time-solver","sublinear"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe vulnerability (CVE-2026-55609) stems from improper input validation within the Model Context Protocol (MCP) tool implementations for the \u003ccode\u003econsciousness-explorer\u003c/code\u003e and \u003ccode\u003esublinear-time-solver\u003c/code\u003e packages. Specifically, the \u003ccode\u003eexport_state\u003c/code\u003e, \u003ccode\u003eimport_state\u003c/code\u003e, \u003ccode\u003esaveVectorToFile\u003c/code\u003e, and \u003ccode\u003eloadVectorFromFile\u003c/code\u003e tools process user-supplied \u003ccode\u003efilepath\u003c/code\u003e arguments by passing them directly to Node.js \u003ccode\u003efs.writeFileSync\u003c/code\u003e and \u003ccode\u003efs.readFileSync\u003c/code\u003e calls without sanitization.\u003c/p\u003e\n\u003cp\u003eThis lack of path confinement enables path traversal attacks, where an attacker can supply sequences such as \u003ccode\u003e../../\u003c/code\u003e to escape the intended directory. Because the application processes these inputs with the privileges of the server user, an attacker can overwrite critical system files, including \u003ccode\u003e~/.ssh/authorized_keys\u003c/code\u003e or application binaries, facilitating privilege escalation or remote code execution. This affects \u003ccode\u003econsciousness-explorer\u003c/code\u003e prior to 1.1.2, \u003ccode\u003esublinear-time-solver\u003c/code\u003e prior to 1.6.0, and the \u003ccode\u003esublinear\u003c/code\u003e crate prior to 0.2.0.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary file write capabilities, compromising the integrity of the server host. This poses a significant risk if the MCP server is exposed to untrusted clients, as an attacker could gain control over the host environment by overwriting configuration files or injecting malicious scripts into execution paths.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003econsciousness-explorer\u003c/code\u003e to 1.1.2 or later, \u003ccode\u003esublinear-time-solver\u003c/code\u003e to 1.6.0 or later, and \u003ccode\u003esublinear\u003c/code\u003e to 0.2.0 or later to apply the path-confinement and basename-only contract fixes.\u003c/li\u003e\n\u003cli\u003eImplement the recommended environment variables \u003ccode\u003eCONSCIOUSNESS_EXPLORER_STATE_DIR\u003c/code\u003e and \u003ccode\u003eSUBLINEAR_SOLVER_VECTOR_DIR\u003c/code\u003e to enforce state file storage in dedicated, non-sensitive directories.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege by running the MCP server under a dedicated, restricted-privilege user account.\u003c/li\u003e\n\u003cli\u003eAudit logs for the \u003ccode\u003eexport_state\u003c/code\u003e and \u003ccode\u003eimport_state\u003c/code\u003e MCP tool calls to identify attempts to supply non-basename paths or path traversal sequences.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T18:48:49Z","date_published":"2026-08-25T18:48:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sublinear-arbitrary-file-write/","summary":"An arbitrary file write vulnerability (CVE-2026-55609) in consciousness-explorer and sublinear-time-solver MCP tools allows path traversal via unconstrained file paths, leading to potential system compromise.","title":"Arbitrary File Write in sublinear-time-solver MCP Tools","url":"https://feed.craftedsignal.io/briefs/2026-08-sublinear-arbitrary-file-write/"}],"language":"en","title":"CraftedSignal Threat Feed - Consciousness-Explorer","version":"https://jsonfeed.org/version/1.1"}