CVE-2026-49291
mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope. Version 10.65.3 patches the issue.
| CWE | CWE-862 |
| Vendor | doobidoo |
| Product | mcp-memory-service |
| Published | Jun 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for doobidoo mcp-memory-service
Be the first to know when new high vulnerabilities affecting doobidoo mcp-memory-service are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Affected Versions
doobidoo / mcp-memory-service
< 10.65.3