mem0ai
Long-term memory for AI Agents
Activity
- Latest release
- 1w ago
- Total releases
- 189
- Cadence
- ~5 days
- Last 12 months
- 35
Details
- License
- Apache-2.0
- First release
- May 18, 2024
| Version | Released | |
|---|---|---|
2.0.20
patch
|
2.0.20
patch
Dependencies (53)
+ 45 more |
|
2.0.19
patch
|
2.0.19
patch
Dependencies (53)
+ 45 more |
|
2.0.18
patch
|
2.0.18
patch
Dependencies (53)
+ 45 more |
|
2.0.17
patch
|
2.0.17
patch
Dependencies (53)
+ 45 more |
|
2.0.16
patch
|
2.0.16
patch
Dependencies (53)
+ 45 more |
|
2.0.15
patch
|
2.0.15
patch
Dependencies (53)
+ 45 more |
|
2.0.14
patch
|
2.0.14
patch
Dependencies (53)
+ 45 more |
|
2.0.13
patch
|
2.0.13
patch
Dependencies (52)
+ 44 more |
|
2.0.12
patch
|
2.0.12
patch
Dependencies (52)
+ 44 more |
|
2.0.11
patch
|
2.0.11
patch
Dependencies (51)
+ 43 more |
|
2.0.10
patch
|
2.0.10
patch
Dependencies (51)
+ 43 more |
|
2.0.8
patch
|
2.0.8
patch
Dependencies (51)
+ 43 more |
|
2.0.7
patch
|
2.0.7
patch
Dependencies (50)
+ 42 more |
|
2.0.6
patch
|
2.0.6
patch
Dependencies (50)
+ 42 more |
|
2.0.5
patch
|
2.0.5
patch
Dependencies (50)
+ 42 more |
|
2.0.4
patch
|
2.0.4
patch
Dependencies (50)
+ 42 more |
|
2.0.3
patch
|
2.0.3
patch
Dependencies (50)
+ 42 more |
|
2.0.2
patch
|
2.0.2
patch
Dependencies (50)
+ 42 more |
|
2.0.1
patch
|
2.0.1
patch
Dependencies (50)
+ 42 more |
|
2.0.0
major
|
2.0.0
major
Dependencies (49)
+ 41 more |
|
2.0.0b2
pre
|
2.0.0b2
pre
Dependencies (49)
+ 41 more |
|
2.0.0b1
pre
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.0b1
pre
Dependencies (49)
+ 41 more |
|
2.0.0b0
pre
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.0b0
pre
Dependencies (53)
+ 45 more |
|
1.0.11
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.11
patch
Dependencies (53)
+ 45 more |
|
1.0.10
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.10
patch
Dependencies (53)
+ 45 more |
|
1.0.9
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.9
patch
Dependencies (53)
+ 45 more |
|
1.0.8
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.8
patch
Dependencies (53)
+ 45 more |
|
1.0.7
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.7
patch
Dependencies (53)
+ 45 more |
|
1.0.6
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.6
patch
Dependencies (52)
+ 44 more |
|
1.0.5
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.5
patch
Dependencies (52)
+ 44 more |
|
1.0.4
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.4
patch
Dependencies (52)
+ 44 more |
|
1.0.3
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.3
patch
Dependencies (52)
+ 44 more |
|
1.0.2
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.2
patch
Dependencies (52)
+ 44 more |
|
1.0.1
patch
1 CVE
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.1
patch
Dependencies (52)
+ 44 more |
|
1.0.0
major
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.0
major
Dependencies (50)
+ 42 more |
|
0.1.118
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.118
patch
Dependencies (48)
+ 40 more |
|
1.0.0b0
pre
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.0b0
pre
Dependencies (48)
+ 40 more |
|
0.1.117
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.117
patch
Dependencies (47)
+ 39 more |
|
0.1.116
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.116
patch
Dependencies (40)
+ 32 more |
|
0.1.115
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.115
patch
Dependencies (38)
+ 30 more |
|
0.1.114
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.114
patch
Dependencies (38)
+ 30 more |
|
0.1.113
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.113
patch
Dependencies (35)
+ 27 more |
|
0.1.112
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.112
patch
Dependencies (35)
+ 27 more |
|
0.1.111
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.111
patch
Dependencies (35)
+ 27 more |
|
0.1.110
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.110
patch
Dependencies (35)
+ 27 more |
|
0.1.109
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.109
patch
Dependencies (35)
+ 27 more |
|
0.1.108
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.108
patch
Dependencies (34)
+ 26 more |
|
0.1.107rc2
pre
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.107rc2
pre
Dependencies (14)
+ 6 more |
|
0.1.107
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.107
patch
Dependencies (14)
+ 6 more |
|
0.1.106
patch
4 CVEs
CVE-2026-31245
PYSEC-2026-2633
GHSA-cgx8-qgvr-f7vf
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31241
PYSEC-2026-2634
GHSA-gq6f-qwv9-rf4j
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-31240
PYSEC-2026-2635
GHSA-jfv9-68m5-gjjr
Jul 13, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 143 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7597
PYSEC-2026-2636
GHSA-xqxw-r767-67m7
Jul 13, 2026
mem0ai mem0 has an Improper Input Validation Issue
Medium
Network
Low
Low
None
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.2
+ 156 more Show less
0.0.20
0.0.20rc1
0.0.21
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.100
0.1.101
0.1.102
0.1.103
0.1.104
0.1.106
0.1.107
0.1.107rc1
0.1.107rc2
0.1.108
0.1.109
0.1.11
0.1.110
0.1.111
0.1.112
0.1.113
0.1.114
0.1.115
0.1.116
0.1.117
0.1.118
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.20a0
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.45rc1
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.52
0.1.53
0.1.54
0.1.55
0.1.56
0.1.57
0.1.58
0.1.59
0.1.6
0.1.60
0.1.61
0.1.62
0.1.63
0.1.65
0.1.66
0.1.67
0.1.69
0.1.7
0.1.70
0.1.71
0.1.72
0.1.73
0.1.74
0.1.75
0.1.76
0.1.77
0.1.78
0.1.78a0
0.1.78a1
0.1.78a2
0.1.79
0.1.8
0.1.80
0.1.81
0.1.81a0
0.1.81a1
0.1.81a2
0.1.82
0.1.83
0.1.84
0.1.84a1
0.1.85
0.1.86
0.1.87
0.1.88
0.1.89
0.1.9
0.1.90
0.1.91
0.1.92
0.1.93
0.1.94
0.1.95
0.1.96
0.1.96rc1
0.1.97
0.1.98
0.1.99
0.1.99a0
0.1.99a1
0.1.99a2
0.1.99a3
1.0.0
1.0.0b0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0b0
2.0.0b1
Fixed in
2.0.0b2
References Updated Jul 13, 2026 · Source: OSV.dev |
0.1.106
patch
Dependencies (14)
+ 6 more |