PT-2026-40322 · Pypi · Mem0
Published
2026-05-12
·
Updated
2026-05-12
·
CVE-2026-31245
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mem0 version 1.0.0
Description
The server lacks authentication and authorization controls for the memory creation API endpoint "POST /memories". This allows unauthenticated users to submit arbitrary memory records without identity or permission verification. A remote attacker can send unauthenticated POST requests to create malicious or spoofed memory entries in the database, resulting in unauthorized data injection and potential data pollution.
Recommendations
Update mem0 version 1.0.0 to a newer version that implements authentication and authorization for the "POST /memories" endpoint.
As a temporary workaround, restrict access to the "POST /memories" API endpoint to minimize the risk of exploitation.
Fix
Missing Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mem0