Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 09 Jul 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | mem0 - Server-Side Request Forgery and Plaintext API Key Exposure via Unauthenticated Config Endpoints | mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url |
Wed, 08 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mem0
Mem0 mem0 |
|
| Vendors & Products |
Mem0
Mem0 mem0 |
Tue, 07 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF attacks by setting ollama_base_url to internal addresses like cloud IMDS via PUT /api/v1/config/mem0/llm endpoint. | |
| Title | mem0 - Server-Side Request Forgery and Plaintext API Key Exposure via Unauthenticated Config Endpoints | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-20T17:45:59.970Z
Reserved: 2026-07-06T15:31:46.187Z
Link: CVE-2026-59706
Updated: 2026-07-08T13:33:40.376Z
Status : Deferred
Published: 2026-07-07T22:16:54.503
Modified: 2026-07-08T15:28:15.630
Link: CVE-2026-59706
No data.
OpenCVE Enrichment
Updated: 2026-07-31T14:15:03Z