Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

mcp-memory-service exposes system details via unauthenticated health endpoint (CVE-2026-29787)

Versions of the open-source mcp-memory-service memory backend prior to 10.21.0 returned detailed system information (OS and Python versions, CPU count, memory, disk usage and database filesystem path) from the /api/health/detailed endpoint without authentication when anonymous access was enabled, exposing reconnaissance data to the network due to the default 0.0.0.0 binding. The issue was patched in version 10.21.0.

Disclosed 7 March 2026 · Record updated 13 September 2026

Impact

Unauthenticated network-accessible disclosure of host system information and database file paths, usable for reconnaissance against deployments of the service.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-29787