Medium severity6.5NVD Advisory· Published May 12, 2026· Updated May 14, 2026
CVE-2026-31243
CVE-2026-31243
Description
The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, leading to the execution of a CREATE TABLE SQL statement. This can cause unexpected table re-creation, schema disruption, potential data loss, and denial of service for the memory management service.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.notion.so/CVE-2026-31243-35d1e139318881c6a6cffbe366c238a6nvdMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.