lowCVSS 6.3Vulnerability
CVE-2026-7597
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.
Properties
- summary
- mem0ai mem0 has an Improper Input Validation Issue
- severity
- low
- epss_score
- 0.00315
- cvss_score
- 6.3
- ghsa_published
- 2026-05-02T00:31:21Z
- source_url
- https://github.com/advisories/GHSA-xqxw-r767-67m7
- ghsa_updated
- 2026-05-07T20:47:22Z
- ghsa_id
- GHSA-xqxw-r767-67m7
- cve_id
- CVE-2026-7597
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.24671
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Improper Input Validation
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]pip/mem0ai
AFFECTS (1)
→[Software]pip/mem0ai
Explore deeper with Ninja Signal's threat intelligence graph