PT-2026-40128 · Pypi · Mem0

Published

2026-05-12

·

Updated

2026-05-14

·

CVE-2026-31241

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions mem0 version 1.0.0
Description The server lacks authentication and authorization controls for the 'DELETE /memories' API endpoint. This allows unauthenticated remote attackers to delete memory records by specifying arbitrary identifiers such as user id, run id, or agent id in the request query parameters, resulting in unauthorized data loss and denial of service.
Recommendations For version 1.0.0, restrict access to the 'DELETE /memories' endpoint or implement proper authentication and authorization controls to prevent unauthorized data deletion.

Fix

DoS

Missing Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31241
GHSA-GQ6F-QWV9-RF4J

Affected Products

Mem0