---
id: CVE-2026-82273
title: >-
  Mastra through 1.63.0 contains an authentication bypass vulnerability in the
  memory API thread ownership validation when mapUserToResourceId callback is
  omitted from configuration
summary: >-
  Mastra through 1.63.0 contains an authentication bypass vulnerability in the
  memory API thread ownership validation when mapUserToResourceId callback is
  omitted from configuration. Authenticated attackers can enumerate all threads
  via GE…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
published: '2026-08-28'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:43.683'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82273'
references:
  - url: 'https://github.com/mastra-ai/mastra'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/mastra-ai/mastra/blob/b7e66f0c478a227985e0062794ef058c3714fabf/packages/server/src/server/handlers/utils.ts
    label: disclosure@vulncheck.com
  - url: 'https://github.com/mastra-ai/mastra/issues/18911'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mastra-memory-api-thread-ownership-check-is-a-no-op-when-mapusertoresourceid-is-unset
    label: disclosure@vulncheck.com
  - url: 'https://github.com/mastra-ai/mastra/issues/18911'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00384
epssPercentile: 0.29764
ingestedAt: '2026-09-23T17:28:14.813Z'
vendor: mastra-ai
product: '@mastra/server'
affected:
  - '@mastra/server <= 1.63.0'
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-28T20:25:03.388875Z'
---

## Overview

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read conversation history and metadata of other resource owners.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
