Threat Advisory

Consciousness Explorer and Sublinear Time Solver Flaw Could Overwrite SSH Keys and Create Unauthorized Access

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A high-severity vulnerability, CVE-2026-55609, with a CVSS score of 7.1, exists in the consciousness-explorer component of sublinear-time-solver due to an external control of file name or path issue. This flaw allows an attacker to write or overwrite any file accessible to the server process by exploiting the MCP export_state tool's direct passing of user-supplied filepath arguments to fs.writeFileSync/fs.readFileSync without constraining the destination or rejecting path traversal. The vulnerability can lead to integrity loss and potential service disruption via the environment template management API.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A high-severity vulnerability, CVE-2026-55609, with a CVSS score of 7.1, exists in the consciousness-explorer component of sublinear-time-solver due to an external control of file name or path issue. This flaw allows an attacker to write or overwrite any file accessible to the server process by exploiting the MCP export_state tool's direct passing of user-supplied filepath arguments to fs.writeFileSync/fs.readFileSync without constraining the destination or rejecting path traversal. The vulnerability can lead to integrity loss and potential service disruption via the environment template management API.[emaillocker id="1283"]

 

RECOMMENDATIONS:

 

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-xc9g-j69q-37xw

[/emaillocker]
crossmenu