{"id":"CVE-2026-82273","title":"Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration","summary":"Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GE…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-862"],"published":"2026-08-28","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:17:43.683","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82273","references":[{"url":"https://github.com/mastra-ai/mastra","label":"disclosure@vulncheck.com"},{"url":"https://github.com/mastra-ai/mastra/blob/b7e66f0c478a227985e0062794ef058c3714fabf/packages/server/src/server/handlers/utils.ts","label":"disclosure@vulncheck.com"},{"url":"https://github.com/mastra-ai/mastra/issues/18911","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/mastra-memory-api-thread-ownership-check-is-a-no-op-when-mapusertoresourceid-is-unset","label":"disclosure@vulncheck.com"},{"url":"https://github.com/mastra-ai/mastra/issues/18911","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00384,"epssPercentile":0.29672,"ingestedAt":"2026-09-23T17:28:14.813Z","vendor":"mastra-ai","product":"@mastra/server","affected":["@mastra/server <= 1.63.0"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-28T20:25:03.388875Z"},"slug":"CVE-2026-82273","body":"## Overview\n\nMastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read conversation history and metadata of other resource owners.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":210243,"id":"CVE-2026-82273","ts":1790264816514,"field":"exploit_available","old":"false","new":"true"}]}