Junglewise Threat Intelligence

CVE-2026-49291: doobidoo mcp-memory-service authorization bypass in JSON-RPC endpoint

CVE-2026-49291 · Severity: high · CVSS 8.1 · Published 2026-06-19

Technologies: mcp-memory-service (PyPI). Vendors: PyPI.

Executive brief

A vulnerability in the mcp-memory-service allows users with restricted "read-only" access to bypass security controls and perform unauthorized actions. Specifically, an attacker can use the Model Context Protocol (MCP) interface to create or delete stored memories, even if their account is explicitly forbidden from doing so via standard interfaces. This could lead to the corruption of the memory database, loss of user data, and unauthorized modification of the information used by AI agents.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the `mcp_endpoint` located in `src/mcp_memory_service/web/api/mcp.py`. While the REST API correctly enforces `require_write_access` for mutating operations, the MCP JSON-RPC endpoint only requires `require_read_access` for the entire `/mcp` route. When processing `tools/call` requests, the service dispatches calls to tools like `store_memory` and `delete_memory` without verifying if the authenticated user possesses the necessary write permissions. An attacker with a valid read-only OAuth token can send a crafted JSON-RPC request to the `/mcp` endpoint to modify or destroy data. The issue is patched in version 10.65.3.

Affected products

  • doobidoo mcp-memory-service <= 10.65.1

Timeline

  • 2026-05-25: disclosed: Advisory published by doobidoo
  • 2026-06-19: advisory: NVD publication date
  • 2026-06-26: advisory: GitHub Advisory Database publication date
  • 2026-06-26: patched: Version 10.65.3 released

References

Related threats