Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqxw-r767-67m7

Опубликовано: 02 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

mem0ai mem0 has an Improper Input Validation Issue

A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.

Пакеты

Наименование

mem0ai

pip
Затронутые версииВерсия исправления

< 2.0.0b2

2.0.0b2

EPSS

Процентиль: 24%
0.00315
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.3
nvd
3 месяца назад

A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.

EPSS

Процентиль: 24%
0.00315
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-20