mem0GHSA-xqxw-r767-67m7
mem0ai mem0 has an Improper Input Validation Issue
Low6.3CVE-2026-7597 · Published May 2, 2026 · updated Jul 13, 2026
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mem0ai PyPI | < 2.0.0b2 | 2.0.0b2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- CVE-2026-7597, PYSEC-2026-2636
More mem0 advisories
All mem0| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 12 | mem0 server lacks authentication and authorization controls for its memory management API endpoints | High7.5 | No fix yet |
| May 12 | mem0 server lacks authentication and authorization controls for its memory deletion API endpoint | Medium6.5 | No fix yet |
| May 12 | mem0 server lacks authentication and authorization controls for its memory creation API endpoint | Medium5.3 | No fix yet |