PT-2026-40128 · Pypi · Mem0
Published
2026-05-12
·
Updated
2026-05-14
·
CVE-2026-31241
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
mem0 version 1.0.0
Description
The server lacks authentication and authorization controls for the 'DELETE /memories' API endpoint. This allows unauthenticated remote attackers to delete memory records by specifying arbitrary identifiers such as
user id, run id, or agent id in the request query parameters, resulting in unauthorized data loss and denial of service.Recommendations
For version 1.0.0, restrict access to the 'DELETE /memories' endpoint or implement proper authentication and authorization controls to prevent unauthorized data deletion.
Fix
DoS
Missing Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mem0