Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mem0ai
Mem0ai mem0 |
|
| Vendors & Products |
Mem0ai
Mem0ai mem0 |
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validating the caller's role. Any authenticated user holding a distributed API key can redirect all LLM and embedder traffic to an attacker-controlled server, with the malicious configuration persisted to PostgreSQL and surviving server restarts to affect all users and API keys on the instance. | |
| Title | Mem0 0.2.8 Missing Authorization via POST /configure Endpoint | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T16:16:42.018Z
Reserved: 2026-06-02T16:30:15.232Z
Link: CVE-2026-49948
No data.
Status : Deferred
Published: 2026-06-09T16:16:43.450
Modified: 2026-06-09T19:36:10.547
Link: CVE-2026-49948
No data.
OpenCVE Enrichment
Updated: 2026-06-09T17:00:09Z