CVE-2026-49948: Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provid...

Added to the CISA Known Exploited Vulnerabilities catalog on 09 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.1.

Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validati...

Required action: Review and patch if applicable to your AI infrastructure.