PT-2026-47811 · Mem0 · Mem0
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Mem0 versions prior to 0.2.8
Description
The self-hosted server component contains a missing authorization flaw. The 'POST /configure' endpoint allows the modification of global LLM provider and embedder configurations. While the system verifies authentication via JWT or
X-API-Key, it fails to validate the caller's role. Consequently, any authenticated user with a distributed API key can redirect all LLM and embedder traffic to a server controlled by an attacker. This malicious configuration is persisted in PostgreSQL and remains active after server restarts, affecting all users and API keys on the instance.Recommendations
Update to the version containing commit ae7f406.
As a temporary workaround, restrict access to the 'POST /configure' endpoint to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mem0