Junglewise Threat Intelligence

CVE-2026-31245: mem0ai mem0 missing authentication in memory creation API

CVE-2026-31245 · Severity: medium · CVSS 5.3 · Published 2026-05-12

Technologies: mem0ai (PyPI). Vendors: PyPI, Mem0ai.

Executive brief

Mem0 is a memory layer used by AI agents to store and retrieve information. A security flaw in the Mem0 server allows anyone on the network to add new information to the database without providing a password or identity. This could allow an attacker to inject false or malicious data into an AI's memory, potentially corrupting its decision-making or polluting the system's data.

Technical details

The mem0 server (version 1.0.0 and earlier) contains a vulnerability where the 'POST /memories' API endpoint does not implement authentication or authorization checks (CWE-306, CWE-862). A remote, unauthenticated attacker can send crafted HTTP POST requests to this endpoint to create new memory records. This allows for unauthorized data injection and data pollution within the database used by AI agents. The vulnerability is exploitable over the network with low complexity and requires no user interaction. As of the advisory date, no patched version has been identified.

Affected products

  • mem0ai mem0ai <= 1.0.0

Timeline

  • 2026-05-12: advisory: GHSA-cgx8-qgvr-f7vf published
  • 2026-05-12: disclosed: CVE-2026-31245 assigned

References

Related threats