VYPR

Voltagent

by VoltAgent

CVEs (2)

  • CVE-2026-82283HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying caller-controlled identifiers to…

  • CVE-2026-13511LowJun 28, 2026
    risk 0.00cvss 3.1epss 0.00

    A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a manipulation of the argument conversationId…