Junglewise Threat Intelligence

CVE-2026-31242: mem0 missing authentication in memory reset endpoint

CVE-2026-31242 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Technologies: Mem0ai Mem0. Vendors: Mem0ai.

Executive brief

A critical security flaw exists in mem0, a memory layer used for AI agents, which allows anyone on the network to delete the entire memory database. Because the system fails to check for user identity or permissions on its reset function, an attacker can permanently erase all stored data. This results in immediate data loss and a complete shutdown of the service for all users.

Technical details

The mem0 v1.0.0 server is vulnerable to missing authentication (CWE-306) and missing authorization (CWE-862) on the 'DELETE /memories' endpoint. An unauthenticated attacker can send a specially crafted HTTP DELETE request to this endpoint, which triggers a backend reset operation. This operation executes a 'DROP TABLE' SQL statement against the memory database table. Successful exploitation results in complete data loss and a permanent denial of service (DoS) until the database schema is restored.

Affected products

  • mem0ai mem0 1.0.0

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: NVD published date

References

Related threats