mcp-memory-service
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mcp-memory-servicepage 1 of 1
- CVE-2026-29787MEDIUMCVSS 5.3EG 5.3✓ Fixed in 10.21.02026-03-07
vulnerable: 10.0.0 ... 9.3.1 (181 versions)
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns detailed system information including OS version, Python version, CPU count, memory totals, di…
- CVE-2026-33010HIGHCVSS 8.8EG 8.8✓ Fixed in 10.25.12026-03-20
vulnerable: 10.0.0 ... 9.3.1 (187 versions)
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], a…
- CVE-2026-49291HIGHCVSS 8.1EG 8.1✓ Fixed in 10.65.32026-06-19
vulnerable: 10.0.0 ... 9.3.1 (289 versions)
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that…
- CVE-2026-50027CRITICALCVSS 9.8EG 9.8✓ Fixed in 10.67.12026-07-02
vulnerable: 10.0.0 ... 9.3.1 (293 versions)
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an …
Check whether mcp-memory-service is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mcp-memory-service CVEs against the assets you own.
Start Free Scan →