Unrated severityNVD Advisory· Published Jun 19, 2026
mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
CVE-2026-49291
Description
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at /mcp requires only OAuth read scope for all requests, then dispatches tools/call directly to handlers that include mutating tools. A read-only OAuth client can call store_memory and delete_memory through MCP even though the corresponding REST endpoints require write scope. Version 10.65.3 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <10.65.3
Patches
Vulnerability mechanics
References
3- github.com/doobidoo/mcp-memory-service/security/advisories/GHSA-2r68-g678-7qr3mitrex_refsource_MISC
- pypi.org/project/mcp-memory-service/10.65.3mitrex_refsource_MISC
- web.archive.org/web/20260508112116/https://github.com/doobidoo/mcp-memory-service/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.