Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2r68-g678-7qr3 | mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call |
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Doobidoo
Doobidoo mcp-memory-service |
|
| Vendors & Products |
Doobidoo
Doobidoo mcp-memory-service |
Fri, 19 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope. Version 10.65.3 patches the issue. | |
| Title | mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-22T17:07:55.536Z
Reserved: 2026-05-28T20:07:58.862Z
Link: CVE-2026-49291
Updated: 2026-06-22T17:07:43.683Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-19T20:30:04Z
Github GHSA