PT-2026-36549 · Mem0 · Mem0

Edoardottt

·

Published

2026-05-01

·

Updated

2026-05-05

·

CVE-2026-7597

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions mem0ai mem0 versions prior to 1.0.12
Description An unsafe deserialization issue exists in the pickle.load() and pickle.dump() functions within the mem0/vector stores/faiss.py file. This allows a remote attacker to perform a manipulation that results in deserialization, which is the process of converting a byte stream back into an object.
Recommendations Apply patch 62dca096f9236010ca15fea9ba369ba740b86b7a to resolve the issue. As a temporary workaround, restrict the use of the pickle.load() and pickle.dump() functions in the mem0/vector stores/faiss.py file.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7597
GHSA-XQXW-R767-67M7

Affected Products

Mem0