A vulnerability was found in cdeust Cortex up to 3.17.0. It has been rated as problematic. This impacts the function
_is_cortex_root of the file mcp_server/server/visualize_bootstrap.py of the component Root Validation. The manipulation of the argument CLAUDE_PROJECT_DIR leads to code injection.
This vulnerability is uniquely identified as CVE-2026-49986. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.