CVE-2026-49291
- EPSS 0.26%
- Veröffentlicht 19.06.2026 17:59:48
- Zuletzt bearbeitet 23.06.2026 15:59:21
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mu...
CVE-2026-33010
- EPSS 0.39%
- Veröffentlicht 20.03.2026 18:33:39
- Zuletzt bearbeitet 14.04.2026 18:12:23
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_creden...
CVE-2026-29787
- EPSS 0.37%
- Veröffentlicht 07.03.2026 15:34:46
- Zuletzt bearbeitet 11.03.2026 20:39:21
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns detailed system information including OS version, Python version, CPU count, memory totals, disk usage, a...