Impact
The vulnerability in VoltAgent’s memory API handlers allows authenticated users to bypass ownership verification. As a result attackers can read, modify, and delete conversations and messages belonging to other users without any further privileges. This leads to data disclosure and tampering across all affected user accounts.
Affected Systems
VoltAgent versions up to and including 2.1.20 are affected. The issue resides in the server core memory handlers and affects all deployed instances of the product that have not applied the public update.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high impact when exploited. Attackers only need legitimate credentials and the ability to send crafted requests to the memory endpoints. Although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the severity and the requirement of authenticated access make it a significant risk for organizations relying on VoltAgent for private conversations.
OpenCVE Enrichment