CVE-2026-29787Disclosure(doobidoo / mcp-memory-service)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns detailed system information including OS version, Python version, CPU count, memory totals, disk usage, and the full database filesystem path. When MCP_ALLOW_ANONYMOUS_ACCESS=true is set (required for the HTTP server to function without OAuth/API key), this endpoint is accessible without authentication. Combined with the default 0.0.0.0 binding, this exposes sensitive reconnaissance data to the entire network. This issue has been patched in version 10.21.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp-memory-service

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-07); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
mcp-memory-service

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-12: 1Mentions · 2026-05-11: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-12: 1Technical Details · 2026-05-11: 103-0703-1205-11
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-072
Disclosure1General1
2026-03-121
General1
2026-05-111
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29787 Information Disclosure in mcp-memory-service Detailed Health Endpoint Before 10.21.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29787

    Post summary

    The entry announces CVE‑2026‑29787, an information disclosure issue in the mcp‑memory‑service health endpoint affecting versions prior to 10.21.0, with no PoC, exploit, or patch details provided.

    00010139
    4.0K followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-29787: How Unauthenticated Health Endpoints Expose MCP Memory Services https://moltx.io/articles/5368d047-3db7-4cd2-8630-8f67ad405e6f

    Post summary

    The article announces CVE-2026-29787, detailing how unauthenticated health endpoints expose MCP memory services, but does not provide a PoC, exploit, or patch information.

    0000022
    5 followersView on X
  • DailyCVE@dailycve
    General

    🟠 mcp-memory-service, Information Disclosure, #CVE-2026-29787 (MEDIUM) https://dailycve.com/mcp-memory-service-information-disclosure-cve-2026-29787-medium/

    Post summary

    The post lists CVE-2026-29787 as an information disclosure vulnerability with medium severity and provides a link to a CVE article, but offers no actionable details about exploitation or mitigation.

    0000042
    167 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-29787 mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns detailed system infor… https://www.cve.org/CVERecord?id=CVE-2026-29787

    Post summary

    The text provides a brief mention of CVE-2026-29787, noting a detail about the /api/health/detailed endpoint in mcp-memory-service before version 10.21.0, but offers no proof of exploit, patch, or in-depth technical details.

    00000109
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdoobidoomcp-memory-service---

Explore more