Mem0 Authentication Bypass Vulnerability in Memory Creation API Endpoint

Vulnerability

A vulnerability exists in the Mem0 server version 1.0.0, specifically in the memory creation API endpoint (POST /memories). The endpoint lacks proper authentication and authorization, allowing unauthenticated users to submit arbitrary memory records. This vulnerability can be exploited by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution.

Impact

Exploitation of this vulnerability allows for unauthorized data injection into the application's database, creating malicious or spoofed memory entries that can disrupt the integrity of the application's data.

Added: May 12, 2026, 6:21 PM
Updated: May 12, 2026, 6:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
0.0
relevance
8.1
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.