An unauthenticated vulnerability exists in mem0's config API endpoints, exposing plaintext LLM API keys and allowing server-side request forgery… (CVE-2026-59706)
An unauthenticated vulnerability exists in mem0's config API endpoints, exposing plaintext LLM API keys and allowing server-side request forgery (SSRF) via the attacker-controlled ollama_base_url parameter. Attackers can retrieve sensitive secrets such as OpenAI API keys through a GET request or trigger SSRF by modifying the ollama_base_url to access internal resources. This vulnerability does not have a confirmed patch and is rated critical in severity.
AI Analysis
Technical Summary
The mem0 component exposes unauthenticated configuration API endpoints that leak large language model (LLM) API keys in plaintext. Specifically, the GET /api/v1/config/ endpoint allows retrieval of stored secrets without authentication. Additionally, the PUT /api/v1/config/mem0/llm endpoint accepts an attacker-controlled ollama_base_url parameter, which can be manipulated to perform server-side request forgery (SSRF) attacks targeting internal network resources such as cloud instance metadata services (IMDS). This vulnerability is tracked as CVE-2026-59706 and is classified under CWE-306 (Missing Authentication for Critical Function). No patch or official remediation has been provided in the available data.
Potential Impact
Unauthenticated attackers can obtain sensitive API keys in plaintext, potentially compromising LLM service credentials. The SSRF capability allows attackers to make unauthorized requests from the vulnerable server to internal services, which may lead to further internal network compromise or data leakage. The combination of secret exposure and SSRF significantly increases the risk of unauthorized access and lateral movement within affected environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the affected API endpoints by implementing network-level controls or authentication proxies to prevent unauthenticated access. Monitor for unusual requests targeting the config API endpoints and consider disabling or restricting the ollama_base_url configuration if possible.
An unauthenticated vulnerability exists in mem0's config API endpoints, exposing plaintext LLM API keys and allowing server-side request forgery… (CVE-2026-59706)
Description
An unauthenticated vulnerability exists in mem0's config API endpoints, exposing plaintext LLM API keys and allowing server-side request forgery (SSRF) via the attacker-controlled ollama_base_url parameter. Attackers can retrieve sensitive secrets such as OpenAI API keys through a GET request or trigger SSRF by modifying the ollama_base_url to access internal resources. This vulnerability does not have a confirmed patch and is rated critical in severity.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The mem0 component exposes unauthenticated configuration API endpoints that leak large language model (LLM) API keys in plaintext. Specifically, the GET /api/v1/config/ endpoint allows retrieval of stored secrets without authentication. Additionally, the PUT /api/v1/config/mem0/llm endpoint accepts an attacker-controlled ollama_base_url parameter, which can be manipulated to perform server-side request forgery (SSRF) attacks targeting internal network resources such as cloud instance metadata services (IMDS). This vulnerability is tracked as CVE-2026-59706 and is classified under CWE-306 (Missing Authentication for Critical Function). No patch or official remediation has been provided in the available data.
Potential Impact
Unauthenticated attackers can obtain sensitive API keys in plaintext, potentially compromising LLM service credentials. The SSRF capability allows attackers to make unauthorized requests from the vulnerable server to internal services, which may lead to further internal network compromise or data leakage. The combination of secret exposure and SSRF significantly increases the risk of unauthorized access and lateral movement within affected environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the affected API endpoints by implementing network-level controls or authentication proxies to prevent unauthenticated access. Monitor for unusual requests targeting the config API endpoints and consider disabling or restricting the ollama_base_url configuration if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-225m-p565-9h68
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-59706"]
- Ecosystems
- []
- Database Specific Severity
- CRITICAL
- Cvss Version
- 4.0
Threat ID: 6a4e4ee2c9d9e3dbe3289529
Added to database: 07/08/2026, 13:21:38 UTC
Last enriched: 07/08/2026, 13:36:50 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.