lowCVSS 6.3Vulnerability

CVE-2026-7597

A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.

Properties

summary
mem0ai mem0 has an Improper Input Validation Issue
severity
low
epss_score
0.00315
cvss_score
6.3
ghsa_published
2026-05-02T00:31:21Z
source_url
https://github.com/advisories/GHSA-xqxw-r767-67m7
ghsa_updated
2026-05-07T20:47:22Z
ghsa_id
GHSA-xqxw-r767-67m7
cve_id
CVE-2026-7597
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.24671

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/mem0ai

AFFECTS (1)

[Software]pip/mem0ai

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7597 (CVSS 6.3) — Ninja Signal Threat Intelligence | Ninja Signal