CVE 9.1 CRITICAL

CVE-2026-31242_CVE-2026-31242

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, leading to the execution of a DROP TABLE SQL statement. This results in the deletion of the entire memory database table, causing catastrophic data loss and a complete denial of service for all users of the service.

AI Analysis

Unauthenticated memory reset vulnerability leading to data loss and denial of service

Basic Information

ID CVE-2026-31242
Source mitre
Published May 12, 2026 at 00:00
Modified May 13, 2026 at 13:54

Affected Product

Vendor mem0ai
Product mem0
Version v1.0.0
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor mem0ai
Product mem0
Version v1.0.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.