mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
Unauthenticated attackers can read, add, or delete stored memory data remotely, breaking confidentiality and integrity.

2 CRIT · 7 HIGH · 1 MED · 2 INFO · THREAT RED · 12 items · Generated in 277s
Unauthenticated attackers can read, add, or delete stored memory data remotely, breaking confidentiality and integrity.
Unauthenticated attackers can run OS commands on the server, leading to full host compromise if exposed.
Unauthenticated SSRF can reach cloud metadata or internal services despite the patch, enabling internal access or credential exposure.
It can expose internal services and cloud credentials via SSRF and redirect users to attacker-controlled URLs.
Unauthenticated clients may hijack the default Telegram session and access account-linked MCP tools remotely.
A hook token could trigger CLI runs with owner-only MCP tool access, breaking privilege boundaries and enabling unauthorized actions.
An attacker can read sensitive local files and upload them to Confluence, exposing keys, configs, and other secrets.
Auth bypass let unauthenticated requests reach MCP tools, exposing connected AI capabilities until patched.
Auto-loading MCP servers from a repo can trigger code execution and expose cloud credentials from a developer workstation.
Faster exploit timelines push vendors to ship patches sooner, affecting defender patch planning and maintenance windows.
This is a SOC awareness piece about response speed, not a specific AI security vulnerability or exploit.
Shows AI deployments are creating real security incidents, often from weak governance, rushed rollout, and poor risk review.