Vulnerability Description
The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, leading to the execution of a DROP TABLE SQL statement. This results in the deletion of the entire memory database table, causing catastrophic data loss and a complete denial of service for all users of the service.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mem0 | Mem0 | 1.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/mem0ai/mem0Product
- https://www.notion.so/CVE-2026-31242-35d1e1393188819c9ebec0e684b4e656MitigationThird Party Advisory
FAQ
What is CVE-2026-31242?
CVE-2026-31242 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE re...
How severe is CVE-2026-31242?
CVE-2026-31242 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-31242?
Check the references section above for vendor advisories and patch information. Affected products include: Mem0 Mem0.