Critical Vulnerability in MemOS npm Package: What You Need to Know
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- memos (npm)
- Affected versions
- >= v2.0.30, <= v2.0.30 or >= memos-local-plugin-v2.0.14-beta.1, <= memos-local-plugin-v2.0.14-beta.1 or >= v2.0.27, <= v2.0.27 or >= v2.0.25, <= v2.0.25 or >= v2.0.24, <= v2.0.24 or >= v2.0.23, <= v2.0.23 or >= v2.0.22, <= v2.0.22 or >= v2.0.20, <= v2.0.20 or >= v2.0.19, <= v2.0.19 or >= v2.0.17, <= v2.0.17 or >= v2.0.16, <= v2.0.16 or >= v2.0.15, <= v2.0.15 or >= v2.0.13, <= v2.0.13 or >= v2.0.12, <= v2.0.12 or >= v2.0.11, <= v2.0.11 or >= v2.0.10, <= v2.0.10 or >= v2.0.8, <= v2.0.8 or >= v2.0.9, <= v2.0.9 or >= v2.0.7, <= v2.0.7 or >= v2.0.6, <= v2.0.6 or >= v2.0.5, <= v2.0.5 or >= v2.0.4, <= v2.0.4 or >= v2.0.2, <= v2.0.2 or >= v2.0.1, <= v2.0.1 or >= v2.0.0, <= v2.0.0 or >= v1.1.3, <= v1.1.3 or >= v1.1.1, <= v1.1.1 or >= v1.1.0, <= v1.1.0 or >= v1.0.1, <= v1.0.1 or >= v1.0.0, <= v1.0.0 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.13, <= v0.1.13 or >= v0.1.12, <= v0.1.12
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the MemOS npm package, which could allow unauthenticated remote attackers to gain admin-level access to API-key management endpoints.
What happened
The MemOS npm package, versions >= v2.0.30, <= v2.0.30 or >= memos-local-plugin-v2.0.14-beta.1, <= memos-local-plugin-v2.0.14-beta.1 or >= v2.0.27, <= v2.0.27 or >= v2.0.25, <= v2.0.25 or >= v2.0.24, <= v2.0.24 or >= v2.0.23, <= v2.0.23 or >= v2.0.22, <= v2.0.22 or >= v2.0.20, <= v2.0.20 or >= v2.0.19, <= v2.0.19 or >= v2.0.17, <= v2.0.17 or >= v2.0.16, <= v2.0.16 or >= v2.0.15, <= v2.0.15 or >= v2.0.13, <= v2.0.13 or >= v2.0.12, <= v2.0.12 or >= v2.0.11, <= v2.0.11 or >= v2.0.10, <= v2.0.10 or >= v2.0.8, <= v2.0.8 or >= v2.0.9, <= v2.0.9 or >= v2.0.7, <= v2.0.7 or >= v2.0.6, <= v2.0.6 or >= v2.0.5, <= v2.0.5 or >= v2.0.4, <= v2.0.4 or >= v2.0.2, <= v2.0.2 or >= v2.0.1, <= v2.0.1 or >= v2.0.0, <= v2.0.0 or >= v1.1.3, <= v1.1.3 or >= v1.1.1, <= v1.1.1 or >= v1.1.0, <= v1.1.0 or >= v1.0.1, <= v1.0.1 or >= v1.0.0, <= v1.0.0 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.13, <= v0.1.13 or >= v0.1.12, <= v0.1.12, reportedly contains a critical vulnerability. This vulnerability allows unauthenticated remote attackers to access admin API-key management endpoints due to a failed internal request check. Attackers can mint API keys, enumerate keys, revoke keys, and generate a master key for persistent privileged access.
The vulnerability arises from a failed check in the is_internal_request() function when the INTERNAL_SERVICE_SECRET environment variable is unset. This results in the comparison None == None evaluating true, treating the request as a trusted internal principal and granting it full scopes. The affected versions of MemOS do not perform this check correctly, leaving the API-key management endpoints exposed.
What to do about it
- Monitor the primary sources for updates on a patch release.
- If using any of the affected versions of MemOS, prepare to upgrade to the latest version once a patch is available.
- Rotate any API keys that may have been compromised as a precaution.
- Ensure that the INTERNAL_SERVICE_SECRET environment variable is set in your deployment to mitigate the risk of this vulnerability.
- Review your deployment configurations to ensure that all security-related environment variables are correctly set.
How 0Day would have caught this
memos is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using any version of the MemOS npm package >= v2.0.30, <= v2.0.30 or >= memos-local-plugin-v2.0.14-beta.1, <= memos-local-plugin-v2.0.14-beta.1 or >= v2.0.27, <= v2.0.27 or >= v2.0.25, <= v2.0.25 or >= v2.0.24, <= v2.0.24 or >= v2.0.23, <= v2.0.23 or >= v2.0.22, <= v2.0.22 or >= v2.0.20, <= v2.0.20 or >= v2.0.19, <= v2.0.19 or >= v2.0.17, <= v2.0.17 or >= v2.0.16, <= v2.0.16 or >= v2.0.15, <= v2.0.15 or >= v2.0.13, <= v2.0.13 or >= v2.0.12, <= v2.0.12 or >= v2.0.11, <= v2.0.11 or >= v2.0.10, <= v2.0.10 or >= v2.0.8, <= v2.0.8 or >= v2.0.9, <= v2.0.9 or >= v2.0.7, <= v2.0.7 or >= v2.0.6, <= v2.0.6 or >= v2.0.5, <= v2.0.5 or >= v2.0.4, <= v2.0.4 or >= v2.0.2, <= v2.0.2 or >= v2.0.1, <= v2.0.1 or >= v2.0.0, <= v2.0.0 or >= v1.1.3, <= v1.1.3 or >= v1.1.1, <= v1.1.1 or >= v1.1.0, <= v1.1.0 or >= v1.0.1, <= v1.0.1 or >= v1.0.0, <= v1.0.0 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.13, <= v0.1.13 or >= v0.1.12, <= v0.1.12.
What should I do right now?
Monitor the primary sources for updates on a patch release. If using any of the affected versions of MemOS, prepare to upgrade to the latest version once a patch is available. Rotate any API keys that may have been compromised as a precaution. Ensure that the INTERNAL_SERVICE_SECRET environment variable is set in your deployment to mitigate the risk of this vulnerability. Review your deployment configurations to ensure that all security-related environment variables are correctly set.
Is there an official fix available yet?
No official fix has been published yet. Monitor the primary sources for updates on a patch release.
How severe is this vulnerability?
This vulnerability is classified as CRITICAL with a CVSS score of 9.8.