mcp-memory-service exposes system details via unauthenticated health endpoint (CVE-2026-29787)
Versions of the open-source mcp-memory-service memory backend prior to 10.21.0 returned detailed system information (OS and Python versions, CPU count, memory, disk usage and database filesystem path) from the /api/health/detailed endpoint without authentication when anonymous access was enabled, exposing reconnaissance data to the network due to the default 0.0.0.0 binding. The issue was patched in version 10.21.0.
Disclosed 7 March 2026 · Record updated 13 September 2026
Impact
Unauthenticated network-accessible disclosure of host system information and database file paths, usable for reconnaissance against deployments of the service.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-29787
