HIGH 7.5
GHSA-jfv9-68m5-gjjr
mem0 server lacks authentication and authorization controls for its memory management API endpoints
Details
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / mem0ai
Introduced in:
0 No fixed version published yet for mem0ai (pip). Pin to a known-safe version or switch to an alternative.