CVE record published for critical unauthenticated document API in mcp-memory-service, whose GitHub repository disappeared and has since returned
CVE-2026-50027 was published to the National Vulnerability Database on 2026-08-14 with a CVSS score of 9.8, covering mcp-memory-service versions before 10.67.1. All HTTP routes under /api/documents/* were served without authentication even when the server was configured with an API key or OAuth, letting an unauthenticated remote attacker write, read, and delete stored memory content. The underlying GitHub advisory was published 2026-07-02. The project's GitHub repository and maintainer account returned 404 when checked on 2026-08-14; both were live again by 2026-08-25, and the project's release notes now state that development moved to Codeberg at the end of May 2026 with the GitHub repository reinstated as a mirror.
A CVE record for mcp-memory-service, a semantic memory MCP server
distributed on PyPI, was published to the National Vulnerability
Database on 2026-08-14 as CVE-2026-50027, with a CVSS score of 9.8. In
versions before 10.67.1, every HTTP route under /api/documents/* was
served without any authentication dependency, even when the server was
configured with an API key via MCP_API_KEY or with OAuth. An
unauthenticated remote attacker could upload arbitrary content into
the memory store, retrieve stored document content, and permanently
delete memories.
The gap was one-sided: the advisory notes the adjacent
/api/memories endpoints enforced authentication correctly. The fix
shipped in 10.67.1. The underlying GitHub advisory,
GHSA-84hp-mqvj-3p8h, was published to the global advisory database on
2026-07-02, six weeks before the NVD record.
The project's public footprint changed around the record's publication, then changed back. The repository the advisory names, doobidoo/mcp-memory-service, returned HTTP 404 when checked on 2026-08-14, as did the maintainer account, and the NVD record cites a web.archive.org snapshot of the repository rather than a live page. PyPI distribution continued through the gap, with 11.8.0 uploaded 2026-08-09 and the package metadata carrying no repository link.
Update, 2026-08-25: the repository and the maintainer account are live again, and the project has explained the arrangement. The v11.8.1 release notes, published on GitHub 2026-08-22, state that development moved to Codeberg at the end of May 2026, that the GitHub repository now operates as a mirror, and that every release from v10.71.0 through v11.8.1 shipped on Codeberg in the interim while PyPI and Docker Hub distribution continued as usual. The PyPI metadata for the current release, 11.8.4, once more links the GitHub repository as its homepage after carrying no repository link when checked on 2026-08-14. What the fetched sources still do not state is why the GitHub repository and account 404'd rather than redirecting during the move. The project has also published a new critical advisory since: an OAuth authorization bypass fixed in v11.8.2, covered separately.
How was this verified, and what are the sources?
Published · last verified · confidence 1.00.
- NVD record for CVE-2026-50027 (published 2026-08-14, CVSS 9.8 critical) - prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth; an unauthenticated remote attacker can upload arbitrary content into the memory store, retrieve stored document content, and delete memories - accessed
- GitHub global advisory GHSA-84hp-mqvj-3p8h (published 2026-07-02, severity critical) - "mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete"; pip package mcp-memory-service, vulnerable range < 10.67.1, patched in 10.67.1 - accessed
- Negative check - https://github.com/doobidoo/mcp-memory-service, the repository named by the advisory, returned HTTP 404 on 2026-08-14; the maintainer account https://github.com/doobidoo also returned 404, and the NVD record's repository reference points at a web.archive.org snapshot - accessed
- Restoration check - https://github.com/doobidoo/mcp-memory-service and the maintainer account https://github.com/doobidoo both returned HTTP 200 on 2026-08-25; the repository is not archived and shows GitHub releases v11.8.1 published 2026-08-22 and v11.8.2 published 2026-08-23; the README points installation clones, the wiki and the full release archive at codeberg.org/doobidoo/mcp-memory-service - accessed
- mcp-memory-service v11.8.1 release notes (published on GitHub 2026-08-22) - "This repository is a mirror. Development, issues, pull requests and releases happen at https://codeberg.org/doobidoo/mcp-memory-service. The release list here stopped at v10.70.3 at the end of May 2026, when the project moved. Everything from v10.71.0 through v11.8.1 was released on Codeberg in the meantime, and all of it is on PyPI and Docker Hub as usual." - accessed
- PyPI JSON metadata for mcp-memory-service, re-fetched 2026-08-25 - latest release 11.8.4, and the metadata's project_urls again carry Homepage, Repository, Documentation and Issues links pointing at github.com/doobidoo/mcp-memory-service, after carrying no repository or homepage link when checked 2026-08-14 - accessed