Executive brief
mcp-memory-service is a tool used to manage and store memories for AI agents. A security flaw in its document management interface allows anyone on the network to read, add, or delete stored data without a password, even if security features like API keys are enabled. This could lead to the exposure of sensitive private notes or the permanent loss of important stored information.
Technical details
The vulnerability is a Missing Authentication for Critical Function (CWE-306) within the FastAPI-based HTTP REST server. The 'documents.py' router was instantiated without any dependency-level authentication guards, unlike the 'memories.py' router which correctly enforces access controls. An unauthenticated attacker can reach endpoints such as /api/documents/upload, /api/documents/search-content, and /api/documents/remove-by-tags. This allows for full CRUD operations on the memory store, including document retrieval, memory poisoning via arbitrary uploads, and data destruction. The issue is resolved in version 10.67.1 by adding explicit authentication dependencies to the affected routes.
Affected products
- doobidoo mcp-memory-service < 10.67.1
Timeline
- 2026-05-28: disclosed
- 2026-07-02: advisory: Updated advisory published