CVE-2026-31241

MEDIUM

mem0 1.0.0 - Unauthenticated Memory Deletion via DELETE /memories Endpoint

Title source: llm
STIX 2.1

Description

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.

Scores

CVSS v3 6.5
EPSS 0.0039
EPSS Percentile 30.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306 CWE-862
Status published
Products (2)
mem0/mem0 1.0.0
pypi/mem0ai 0 - 1.0.0PyPI
Published May 12, 2026
Tracked Since May 12, 2026