Medium severity6.5NVD Advisory· Published Sep 3, 2026
CVE-2026-85093
CVE-2026-85093
Description
Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/cheshire-cat-ai/core/blob/1.9.2/core/cat/looking_glass/stray_cat.pynvd
- github.com/cheshire-cat-ai/core/blob/1.9.2/core/cat/routes/memory/points.pynvd
- github.com/cheshire-cat-ai/core/issues/1136nvd
- www.vulncheck.com/advisories/cheshire-cat-ai-memory-collection-endpoint-information-disclosurenvd
News mentions
0No linked articles in our index yet.