CVE-2026-59705
mem0 OpenMemory API Unauthenticated Memory Access and Denial of Service
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An unauthenticated access vulnerability exists in mem0's openmemory/api component, allowing attackers to read, write, or delete arbitrary user memories. Attackers can also trigger a denial-of-service affecting all users. This issue is relevant for readers to understand potential unauthorized access to sensitive data an