mcp-memory-service vulnerabilities
CVEs whose affected-version data names the mcp-memory-service package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-50027Critical· 9.8mcp-memory-service is a semantic memory layer for AI applications
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with a…
▾ Midnightmcp-memory-service · mcp-memory-serviceEPSS 0.50%via NVD
CVE-2026-49291High· 8.1mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
▾ Twilightmcp-memory-service · mcp-memory-serviceEPSS 0.49%via GHSA
CVE-2026-33010High· 8.1mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
▾ Twilightmcp-memory-service · mcp-memory-serviceEPSS 0.39%via OSV
CVE-2026-29787Medium· 5.3mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
▾ Sunlitmcp-memory-service · mcp-memory-serviceEPSS 0.37%via OSV