云虫漏洞情报

CVE-2026-82273 - Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read conversation history and metadata of other resource owners. - 漏洞详情

漏洞编号:CVE-2026-82273

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-82273

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-862

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read conversation history and metadata of other resource owners.

相关链接

相关漏洞

« 返回首页