Executive brief
Cheshire Cat AI is an AI agent framework used by companies to build and deploy chatbot applications. An authentication bypass flaw in its memory retrieval API allows authenticated users to access other users' conversation history and personal data. An attacker with basic read permissions can retrieve sensitive information belonging to all users in the system by exploiting missing per-user filtering.
Technical details
The GET /memory/collections/{collection_id}/points endpoint in Cheshire Cat AI fails to apply per-user filtering when retrieving episodic memory points, resulting in broken access control (CWE-284). Authenticated attackers with MEMORY:READ permission can bypass per-user data isolation and retrieve all stored conversation messages and personal data from the collection by paginating through results using the offset cursor. The vulnerability requires valid authentication credentials but does not require elevated privileges. No patch status is currently documented in the advisory.
Affected products
- Cheshire Cat AI Cheshire Cat 1.9.2 and earlier
Timeline
- 2026-09-03: disclosed