Metrics
Affected Vendors & Products
Fri, 28 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mastra-ai
Mastra-ai mastra |
|
| Vendors & Products |
Mastra-ai
Mastra-ai mastra |
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read conversation history and metadata of other resource owners. | |
| Title | Mastra Memory API Thread Ownership Check Is a No-op When mapUserToResourceId Is Unset | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T20:25:25.139Z
Reserved: 2026-08-28T11:12:39.515Z
Link: CVE-2026-82273
Updated: 2026-08-28T20:25:20.730Z
Status : Received
Published: 2026-08-28T20:20:18.227
Modified: 2026-08-28T22:16:56.020
Link: CVE-2026-82273
No data.
OpenCVE Enrichment
Updated: 2026-08-28T22:15:04Z