CVE-2026-59706: mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated att...

Added to the CISA Known Exploited Vulnerabilities catalog on 07 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.3.

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF atta...

Required action: Review and patch if applicable to your AI infrastructure.