CVE-2026-59163: Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then pas...

Added to the CISA Known Exploited Vulnerabilities catalog on 18 Sep 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 9.1.

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with options that effectively disabled signature verification. T...

Required action: Review and patch if applicable to your AI infrastructure.