PT-2026-40322 · Pypi · Mem0

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-31245

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions mem0 version 1.0.0
Description The server lacks authentication and authorization controls for the memory creation API endpoint "POST /memories". This allows unauthenticated users to submit arbitrary memory records without identity or permission verification. A remote attacker can send unauthenticated POST requests to create malicious or spoofed memory entries in the database, resulting in unauthorized data injection and potential data pollution.
Recommendations Update mem0 version 1.0.0 to a newer version that implements authentication and authorization for the "POST /memories" endpoint. As a temporary workaround, restrict access to the "POST /memories" API endpoint to minimize the risk of exploitation.

Fix

Missing Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31245
GHSA-CGX8-QGVR-F7VF

Affected Products

Mem0