Impact
The vulnerability is an unauthenticated access flaw in mem0’s OpenMemory API. Attackers can read, write, and delete any user memory by calling retrieval endpoints. An attacker can exfiltrate private data, and the same flaw also causes denial‑of-service for all users.
Affected Systems
The affected component is mem0’s OpenMemory API. No specific version information is provided, but the flaw exists in the current open‑source implementation as seen in the repository commit linked in the references. Any deployment that uses this API is potentially affected.
Risk and Exploitability
The CVSS critical severity and an EPSS score of less than 1% indicate a low probability of exploitation, yet the vulnerability is not listed in the CISA KEV catalog. The lack of authentication enables attackers to exploit the flaw from any network location that can reach the API, and no credentials are required to do so.
OpenCVE Enrichment