VYPR

mcp-memory-service

by Mcp Memory Service

CVEs (1)

  • CVE-2026-50027criJul 2, 2026
    risk 0.59cvss epss

    ## Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete ### Summary All HTTP routes under `/api/documents/*` in `mcp-memory-service` are served without any authentication dependency, even when the server is configured with an API key…