<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 00:47:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329006</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329006</link>
      <description>EUVD-2026-329006</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329006</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49291</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49291</link>
      <description>&lt;p&gt;mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope. Version 10.65.3 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope. Version 10.65.3 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49291</guid>
    </item>
    <item>
      <title>GHSA-2r68-g678-7qr3 — mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2r68-g678-7qr3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-memory-service&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;`src/mcp_memory_service/web/api/mcp.py` declares `mcp_endpoint` with `user: AuthenticationResult = Depends(require_read_access)`. For `tools/call`, it extracts the requested tool name and arguments, then calls `handle_tool_call(storage, tool_name, arguments)` without passing the authenticated user or checking a per-tool required scope.&lt;/p&gt;
&lt;p&gt;The MCP tool registry includes both read tools and write tools. In the same handler file, `store_memory` creates a `Memory` object and calls `storage.store(...)`, while `delete_memory` calls `storage.delete(content_hash)`. These operations are reachable with only the `read` scope.&lt;/p&gt;
&lt;p&gt;The REST endpoint demonstrates the intended boundary: `POST /api/memories` uses `Depends(require_write_access)` and rejects a read-only token with 403 `insufficient_scope`.&lt;/p&gt;
&lt;p&gt;## Reproduction&lt;/p&gt;
&lt;p&gt;1. Enable OAuth and disable anonymous access.
2. Generate a valid OAuth JWT with only `scope: read`.
3. Confirm the REST write endpoint rejects it:&lt;/p&gt;
&lt;p&gt;```http
POST /api/memories
Authorization: Bearer &amp;lt;read-only-token&amp;gt;
Content-Type: application/json&lt;/p&gt;
&lt;p&gt;{&amp;#34;content&amp;#34;:&amp;#34;rest denied control&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;Expected and observed: HTTP 403 with `Requir…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-memory-service&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;`src/mcp_memory_service/web/api/mcp.py` declares `mcp_endpoint` with `user: AuthenticationResult = Depends(require_read_access)`. For `tools/call`, it extracts the requested tool name and arguments, then calls `handle_tool_call(storage, tool_name, arguments)` without passing the authenticated user or checking a per-tool required scope.&lt;/p&gt;
&lt;p&gt;The MCP tool registry includes both read tools and write tools. In the same handler file, `store_memory` creates a `Memory` object and calls `storage.store(...)`, while `delete_memory` calls `storage.delete(content_hash)`. These operations are reachable with only the `read` scope.&lt;/p&gt;
&lt;p&gt;The REST endpoint demonstrates the intended boundary: `POST /api/memories` uses `Depends(require_write_access)` and rejects a read-only token with 403 `insufficient_scope`.&lt;/p&gt;
&lt;p&gt;## Reproduction&lt;/p&gt;
&lt;p&gt;1. Enable OAuth and disable anonymous access.
2. Generate a valid OAuth JWT with only `scope: read`.
3. Confirm the REST write endpoint rejects it:&lt;/p&gt;
&lt;p&gt;```http
POST /api/memories
Authorization: Bearer &amp;lt;read-only-token&amp;gt;
Content-Type: application/json&lt;/p&gt;
&lt;p&gt;{&amp;#34;content&amp;#34;:&amp;#34;rest denied control&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;Expected and observed: HTTP 403 with `Requir…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2r68-g678-7qr3</guid>
    </item>
    <item>
      <title>PYSEC-2026-2622 — mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2622</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-memory-service&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;`src/mcp_memory_service/web/api/mcp.py` declares `mcp_endpoint` with `user: AuthenticationResult = Depends(require_read_access)`. For `tools/call`, it extracts the requested tool name and arguments, then calls `handle_tool_call(storage, tool_name, arguments)` without passing the authenticated user or checking a per-tool required scope.&lt;/p&gt;
&lt;p&gt;The MCP tool registry includes both read tools and write tools. In the same handler file, `store_memory` creates a `Memory` object and calls `storage.store(...)`, while `delete_memory` calls `storage.delete(content_hash)`. These operations are reachable with only the `read` scope.&lt;/p&gt;
&lt;p&gt;The REST endpoint demonstrates the intended boundary: `POST /api/memories` uses `Depends(require_write_access)` and rejects a read-only token with 403 `insufficient_scope`.&lt;/p&gt;
&lt;p&gt;## Reproduction&lt;/p&gt;
&lt;p&gt;1. Enable OAuth and disable anonymous access.
2. Generate a valid OAuth JWT with only `scope: read`.
3. Confirm the REST write endpoint rejects it:&lt;/p&gt;
&lt;p&gt;```http
POST /api/memories
Authorization: Bearer &amp;lt;read-only-token&amp;gt;
Content-Type: application/json&lt;/p&gt;
&lt;p&gt;{&amp;#34;content&amp;#34;:&amp;#34;rest denied control&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;Expected and observed: HTTP 403 with `Requir…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-memory-service&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;`src/mcp_memory_service/web/api/mcp.py` declares `mcp_endpoint` with `user: AuthenticationResult = Depends(require_read_access)`. For `tools/call`, it extracts the requested tool name and arguments, then calls `handle_tool_call(storage, tool_name, arguments)` without passing the authenticated user or checking a per-tool required scope.&lt;/p&gt;
&lt;p&gt;The MCP tool registry includes both read tools and write tools. In the same handler file, `store_memory` creates a `Memory` object and calls `storage.store(...)`, while `delete_memory` calls `storage.delete(content_hash)`. These operations are reachable with only the `read` scope.&lt;/p&gt;
&lt;p&gt;The REST endpoint demonstrates the intended boundary: `POST /api/memories` uses `Depends(require_write_access)` and rejects a read-only token with 403 `insufficient_scope`.&lt;/p&gt;
&lt;p&gt;## Reproduction&lt;/p&gt;
&lt;p&gt;1. Enable OAuth and disable anonymous access.
2. Generate a valid OAuth JWT with only `scope: read`.
3. Confirm the REST write endpoint rejects it:&lt;/p&gt;
&lt;p&gt;```http
POST /api/memories
Authorization: Bearer &amp;lt;read-only-token&amp;gt;
Content-Type: application/json&lt;/p&gt;
&lt;p&gt;{&amp;#34;content&amp;#34;:&amp;#34;rest denied control&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;Expected and observed: HTTP 403 with `Requir…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2622</guid>
    </item>
  </channel>
</rss>
