CVE-2026-33010General(doobidoo / mcp-memory-service)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch doobidoo mcp-memory-service systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_credentials=True, allow_methods=["*"], and allow_headers=["*"]. The wildcard Access-Control-Allow-Origin: * header permits any website to read API responses cross-origin. When combined with anonymous access (MCP_ALLOW_ANONYMOUS_ACCESS=true) - the simplest way to get the HTTP dashboard working without OAuth - no credentials are needed, so any malicious website can silently read, modify, and delete all stored memories. This issue has been patched in version 10.25.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-942

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp-memory-service

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
mcp-memory-service

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-27: 103-2003-2203-27
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-221
General1
2026-03-271
General1
Full discourse3 posts
  • IntegSec@integ_sec
    General

    CVE-2026-33010: mcp-memory-service Cross-Origin Memory Theft - What It Means for Your Business and How to Respond https://hubs.li/Q048DJrD0

    Post summary

    The text announces a CVE with a brief description of a cross‑origin memory theft vulnerability but provides no detailed technical data, exploit code, or patch information, making it a general advisory.

    0000031
    31 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33010 mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the ap… https://www.cve.org/CVERecord?id=CVE-2026-33010

    Post summary

    The text briefly notes a CVE affecting mcp-memory-service before version 10.25.1 when the HTTP server is enabled, but it offers none of the detailed technical, exploit, patch, or mitigation information.

    0000090
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33010 - High mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures Fast... https://www.thehackerwire.com/vulnerability/CVE-2026-33010/ https://t.co/5TyQA4Dzkx

    Post summary

    The tweet announces a new high‑severity vulnerability (CVE‑2026‑33010) in mcp‑memory‑service, indicating it is fixed in version 10.25.1 and linking to a detailed article.

    0000041
    138 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdoobidoomcp-memory-service---

Explore more