GHSA-cx5g-gfhq-8qmjHighCVSS 6.5

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user...

Published
September 3, 2026
Last Modified
September 3, 2026

🔗 CVE IDs covered (1)

📋 Description

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.

🔗 References (7)