mcp-memory-service
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mcp-memory-servicepage 1 of 1
- CVE-2026-33010HIGHCVSS 8.1EG 8.1✓ Fixed in 10.25.12026-03-20
vulnerable: 10.0.0 ... 9.3.1 (187 versions)
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], a…
- CVE-2026-49291HIGHCVSS 8.1EG 8.1✓ Fixed in 10.65.32026-06-19
vulnerable: 10.0.0 ... 9.3.1 (289 versions)
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that…
- CVE-2026-50027CRITICALCVSS 9.8EG 9.8✓ Fixed in 10.67.12026-07-02
vulnerable: 10.0.0 ... 9.3.1 (293 versions)
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete ## Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete ### Summary All HTT…
Check whether mcp-memory-service is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mcp-memory-service CVEs against the assets you own.
Start Free Scan →