Executive brief
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
Affected products
- PyPI mcp-memory-service
Junglewise Threat Intelligence
CVE-2026-33010 · Severity: low · CVSS 3.1 · Published 2026-07-13
Technologies: mcp-memory-service (PyPI). Vendors: PyPI.
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft