<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T07:20:38.188451+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329006</id>
    <title>EUVD-2026-329006</title>
    <updated>2026-10-07T07:20:38.265672+00:00</updated>
    <content>EUVD-2026-329006</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49291</id>
    <title>fkie_cve-2026-49291</title>
    <updated>2026-10-07T07:20:38.265719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope. Version 10.65.3 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2r68-g678-7qr3</id>
    <title>GHSA-2r68-g678-7qr3 — mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call</title>
    <updated>2026-10-07T07:20:38.265757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mcp-memory-service</p>
<p>## Summary</p>
<p>The HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope.</p>
<p>## Technical Details</p>
<p>`src/mcp_memory_service/web/api/mcp.py` declares `mcp_endpoint` with `user: AuthenticationResult = Depends(require_read_access)`. For `tools/call`, it extracts the requested tool name and arguments, then calls `handle_tool_call(storage, tool_name, arguments)` without passing the authenticated user or checking a per-tool required scope.</p>
<p>The MCP tool registry includes both read tools and write tools. In the same handler file, `store_memory` creates a `Memory` object and calls `storage.store(...)`, while `delete_memory` calls `storage.delete(content_hash)`. These operations are reachable with only the `read` scope.</p>
<p>The REST endpoint demonstrates the intended boundary: `POST /api/memories` uses `Depends(require_write_access)` and rejects a read-only token with 403 `insufficient_scope`.</p>
<p>## Reproduction</p>
<p>1. Enable OAuth and disable anonymous access.
2. Generate a valid OAuth JWT with only `scope: read`.
3. Confirm the REST write endpoint rejects it:</p>
<p>```http
POST /api/memories
Authorization: Bearer &lt;read-only-token&gt;
Content-Type: application/json</p>
<p>{"content":"rest denied control"}
```</p>
<p>Expected and observed: HTTP 403 with `Requir…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2r68-g678-7qr3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2622</id>
    <title>PYSEC-2026-2622 — mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call</title>
    <updated>2026-10-07T07:20:38.265811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mcp-memory-service</p>
<p>## Summary</p>
<p>The HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope.</p>
<p>## Technical Details</p>
<p>`src/mcp_memory_service/web/api/mcp.py` declares `mcp_endpoint` with `user: AuthenticationResult = Depends(require_read_access)`. For `tools/call`, it extracts the requested tool name and arguments, then calls `handle_tool_call(storage, tool_name, arguments)` without passing the authenticated user or checking a per-tool required scope.</p>
<p>The MCP tool registry includes both read tools and write tools. In the same handler file, `store_memory` creates a `Memory` object and calls `storage.store(...)`, while `delete_memory` calls `storage.delete(content_hash)`. These operations are reachable with only the `read` scope.</p>
<p>The REST endpoint demonstrates the intended boundary: `POST /api/memories` uses `Depends(require_write_access)` and rejects a read-only token with 403 `insufficient_scope`.</p>
<p>## Reproduction</p>
<p>1. Enable OAuth and disable anonymous access.
2. Generate a valid OAuth JWT with only `scope: read`.
3. Confirm the REST write endpoint rejects it:</p>
<p>```http
POST /api/memories
Authorization: Bearer &lt;read-only-token&gt;
Content-Type: application/json</p>
<p>{"content":"rest denied control"}
```</p>
<p>Expected and observed: HTTP 403 with `Requir…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2622"/>
  </entry>
</feed>
