Junglewise Threat Intelligence

CVE-2026-59706: mem0 unauthenticated API key exposure and SSRF in config endpoints

CVE-2026-59706 · Severity: critical · CVSS 9.3 · Published 2026-07-07

Vendors: Mem0ai.

Executive brief

mem0, a memory layer for AI agents, contains security flaws in its configuration interface. An unauthorized person can remotely access the system to steal sensitive AI service credentials (like OpenAI API keys) or force the server to perform unauthorized internal network requests. This could lead to significant financial costs from stolen API usage or provide a foothold for attackers to access other private cloud infrastructure.

Technical details

The vulnerability exists in the OpenMemory configuration API (specifically within openmemory/api/app/routers/config.py) due to a lack of authentication (CWE-306). Unauthenticated attackers can perform a GET request to /api/v1/config/ to retrieve stored LLM API keys in plaintext. Additionally, the PUT /api/v1/config/mem0/llm endpoint allows attackers to modify the 'ollama_base_url' without validation. By pointing this URL to internal services (such as the AWS/cloud Instance Metadata Service at 169.254.169.254), an attacker can trigger a Server-Side Request Forgery (SSRF) when the memory client next performs an operation. A patch was committed in version a3154d59e52386d4e1189c1f5f44819868f76514.

Affected products

  • mem0ai mem0ai/mem0 (OpenMemory) <= commit a3154d5

Timeline

  • 2026-06-01: disclosed: Initial report to vendor via email
  • 2026-07-03: other: Public GitHub issue opened after no vendor response
  • 2026-07-07: advisory: NVD and VulnCheck advisory published
  • 2026-07-07: patched: Fix committed to repository

References