
CVE-2026-49291: mcp-memory-service OAuth read-only clients can write/delete memories via MCP tools/call The advisory describes an OAuth scope check placed only at the /mcp JSON-RPC boundary: requests with read scope can still reach tools/call handlers that invoke mutating tools like storememory and deletememory, enabling state changes despite “read-only” authorization. #MCP #AgentSecurity #AISecurity #Advisory https://github.com/advisories/GHSA-2r68-g678-7qr3
Post summary
The advisory discloses an OAuth scope enforcement flaw in MCP’s memory service that allows read‑only clients to write or delete memories via the /mcp JSON‑RPC interface.




