NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-31241
Summary

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.

Publication Date May 13, 2026, 3:16 a.m.
Registration Date May 13, 2026, 4:13 a.m.
Last Update May 13, 2026, 3:16 a.m.
Related information, measures and tools
Common Vulnerabilities List