CVE-2026-59706Patch

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF attacks by setting ollama_base_url to internal addresses like cloud IMDS via PUT /api/v1/config/mem0/llm endpoint.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-07: 107-07
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-59706 — CVSS 9.3/10 █████████░ mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/pVcwg319oI

    Post summary

    Critical vulnerability (CVE-2026-59706) in mem0 exposes LLM API keys via unauthenticated endpoints, CVSS 9.3/10; patch has been released.

    1000084
    63 followersView on X

Explore more