---
id: CVE-2026-19327
title: A flaw has been found in abracadabra50 claude-sesh 1.0.0
summary: >-
  A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects
  the function getEnrichedData/enrichSession of the file
  src/services/enricher.ts. Executing a manipulation of the argument sessionId
  can lead to path traversal. …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-22
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19327'
references:
  - url: 'https://github.com/abracadabra50/claude-sesh/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/abracadabra50/claude-sesh/commit/786c9d74800e6d0858b65778f31beb71b3983a50
    label: cna@vuldb.com
  - url: 'https://github.com/abracadabra50/claude-sesh/issues/2'
    label: cna@vuldb.com
  - url: >-
      https://github.com/abracadabra50/claude-sesh/issues/2#issuecomment-5077347565
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-19327'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/865244'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387161'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387161/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-09T08:33:06.915Z'
epss: 0.00172
epssPercentile: 0.0586
---

## Overview

A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument sessionId can lead to path traversal. The attack needs to be launched locally. This patch is called 786c9d74800e6d0858b65778f31beb71b3983a50. Applying a patch is advised to resolve this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
