NPM · AUGUST 2026 · EARLY WARNING

Critical Vulnerability in MemOS npm Package: What You Need to Know

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
memos (npm)
Affected versions
>= v2.0.30, <= v2.0.30 or >= memos-local-plugin-v2.0.14-beta.1, <= memos-local-plugin-v2.0.14-beta.1 or >= v2.0.27, <= v2.0.27 or >= v2.0.25, <= v2.0.25 or >= v2.0.24, <= v2.0.24 or >= v2.0.23, <= v2.0.23 or >= v2.0.22, <= v2.0.22 or >= v2.0.20, <= v2.0.20 or >= v2.0.19, <= v2.0.19 or >= v2.0.17, <= v2.0.17 or >= v2.0.16, <= v2.0.16 or >= v2.0.15, <= v2.0.15 or >= v2.0.13, <= v2.0.13 or >= v2.0.12, <= v2.0.12 or >= v2.0.11, <= v2.0.11 or >= v2.0.10, <= v2.0.10 or >= v2.0.8, <= v2.0.8 or >= v2.0.9, <= v2.0.9 or >= v2.0.7, <= v2.0.7 or >= v2.0.6, <= v2.0.6 or >= v2.0.5, <= v2.0.5 or >= v2.0.4, <= v2.0.4 or >= v2.0.2, <= v2.0.2 or >= v2.0.1, <= v2.0.1 or >= v2.0.0, <= v2.0.0 or >= v1.1.3, <= v1.1.3 or >= v1.1.1, <= v1.1.1 or >= v1.1.0, <= v1.1.0 or >= v1.0.1, <= v1.0.1 or >= v1.0.0, <= v1.0.0 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.13, <= v0.1.13 or >= v0.1.12, <= v0.1.12
Patched version
Not yet available
CVE-2026-75110

An early warning has been issued for a critical vulnerability in the MemOS npm package, which could allow unauthenticated remote attackers to gain admin-level access to API-key management endpoints.

What happened

The MemOS npm package, versions >= v2.0.30, <= v2.0.30 or >= memos-local-plugin-v2.0.14-beta.1, <= memos-local-plugin-v2.0.14-beta.1 or >= v2.0.27, <= v2.0.27 or >= v2.0.25, <= v2.0.25 or >= v2.0.24, <= v2.0.24 or >= v2.0.23, <= v2.0.23 or >= v2.0.22, <= v2.0.22 or >= v2.0.20, <= v2.0.20 or >= v2.0.19, <= v2.0.19 or >= v2.0.17, <= v2.0.17 or >= v2.0.16, <= v2.0.16 or >= v2.0.15, <= v2.0.15 or >= v2.0.13, <= v2.0.13 or >= v2.0.12, <= v2.0.12 or >= v2.0.11, <= v2.0.11 or >= v2.0.10, <= v2.0.10 or >= v2.0.8, <= v2.0.8 or >= v2.0.9, <= v2.0.9 or >= v2.0.7, <= v2.0.7 or >= v2.0.6, <= v2.0.6 or >= v2.0.5, <= v2.0.5 or >= v2.0.4, <= v2.0.4 or >= v2.0.2, <= v2.0.2 or >= v2.0.1, <= v2.0.1 or >= v2.0.0, <= v2.0.0 or >= v1.1.3, <= v1.1.3 or >= v1.1.1, <= v1.1.1 or >= v1.1.0, <= v1.1.0 or >= v1.0.1, <= v1.0.1 or >= v1.0.0, <= v1.0.0 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.13, <= v0.1.13 or >= v0.1.12, <= v0.1.12, reportedly contains a critical vulnerability. This vulnerability allows unauthenticated remote attackers to access admin API-key management endpoints due to a failed internal request check. Attackers can mint API keys, enumerate keys, revoke keys, and generate a master key for persistent privileged access.

The vulnerability arises from a failed check in the is_internal_request() function when the INTERNAL_SERVICE_SECRET environment variable is unset. This results in the comparison None == None evaluating true, treating the request as a trusted internal principal and granting it full scopes. The affected versions of MemOS do not perform this check correctly, leaving the API-key management endpoints exposed.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If memos is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using any version of the MemOS npm package >= v2.0.30, <= v2.0.30 or >= memos-local-plugin-v2.0.14-beta.1, <= memos-local-plugin-v2.0.14-beta.1 or >= v2.0.27, <= v2.0.27 or >= v2.0.25, <= v2.0.25 or >= v2.0.24, <= v2.0.24 or >= v2.0.23, <= v2.0.23 or >= v2.0.22, <= v2.0.22 or >= v2.0.20, <= v2.0.20 or >= v2.0.19, <= v2.0.19 or >= v2.0.17, <= v2.0.17 or >= v2.0.16, <= v2.0.16 or >= v2.0.15, <= v2.0.15 or >= v2.0.13, <= v2.0.13 or >= v2.0.12, <= v2.0.12 or >= v2.0.11, <= v2.0.11 or >= v2.0.10, <= v2.0.10 or >= v2.0.8, <= v2.0.8 or >= v2.0.9, <= v2.0.9 or >= v2.0.7, <= v2.0.7 or >= v2.0.6, <= v2.0.6 or >= v2.0.5, <= v2.0.5 or >= v2.0.4, <= v2.0.4 or >= v2.0.2, <= v2.0.2 or >= v2.0.1, <= v2.0.1 or >= v2.0.0, <= v2.0.0 or >= v1.1.3, <= v1.1.3 or >= v1.1.1, <= v1.1.1 or >= v1.1.0, <= v1.1.0 or >= v1.0.1, <= v1.0.1 or >= v1.0.0, <= v1.0.0 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.13, <= v0.1.13 or >= v0.1.12, <= v0.1.12.

What should I do right now?

Monitor the primary sources for updates on a patch release. If using any of the affected versions of MemOS, prepare to upgrade to the latest version once a patch is available. Rotate any API keys that may have been compromised as a precaution. Ensure that the INTERNAL_SERVICE_SECRET environment variable is set in your deployment to mitigate the risk of this vulnerability. Review your deployment configurations to ensure that all security-related environment variables are correctly set.

Is there an official fix available yet?

No official fix has been published yet. Monitor the primary sources for updates on a patch release.

How severe is this vulnerability?

This vulnerability is classified as CRITICAL with a CVSS score of 9.8.

Sources

Join the 0Day waitlist →

← Back to all threats