Cheshire Cat AI memory endpoint lacks per-user filtering
Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering, allowing authenticated attackers with MEMORY:READ permission to retrieve all users' conversation messages and personal data through pagination.
Disclosed 3 September 2026 · Record updated 13 September 2026
Impact
Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-cx5g-gfhq-8qmj
