PT-2026-83296 · Mastra · Mastra

·

CVE-2026-82273

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mastra versions prior to 1.63.1
Description An authentication bypass exists in the memory API thread ownership validation. This occurs when the mapUserToResourceId callback is omitted from the configuration. Authenticated attackers can enumerate all threads through the 'GET /api/memory/threads' endpoint and access the conversation history and metadata belonging to other resource owners.
Recommendations Update to a version newer than 1.63.0. Ensure the mapUserToResourceId callback is correctly configured in the memory API settings.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82273

Affected Products

Mastra