CVE-2026-33010 impacts mcp-memory-service, an open-source memory backend for multi-agent systems, in versions prior to 10.25.1. This high-severity vulnerability (CVSS 8.1) is a Cross-Origin Resource Sharing (CORS) misconfiguration (CWE-942) that, when the HTTP server and anonymous access are enabled, allows any malicious website to silently read, modify, and delete all stored memories. The attack requires user interaction but no privileges, leading to high confidentiality and integrity impacts. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been identified. Organizations using affected versions should upgrade to 10.25.1 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.25.1CPE matchmatch criteria | cpe:2.3:a:doobidoo:mcp-memory-service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.