Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xcw4-53cc-hv32 | Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with options that effectively disabled signature verification. The server accepted any well-formed token regardless of the signature, including tokens with alg: none and tokens signed with the wrong key. The fix in v3.10.1 replaces the broken decode with a from-scratch HS256 verifier using only the Python standard library. For users who cannot upgrade immediately, restrict network access to the sync server endpoint to trusted clients only. Firewall, reverse proxy with mTLS, or localhost bind with SSH tunnel are all viable. The vulnerability is not exploitable against an unreachable endpoint. | |
| Title | Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T18:01:56.013Z
Reserved: 2026-07-02T16:50:27.887Z
Link: CVE-2026-59163
Updated: 2026-09-18T18:01:49.553Z
Status : Received
Published: 2026-09-18T18:17:07.807
Modified: 2026-09-18T18:17:07.807
Link: CVE-2026-59163
No data.
OpenCVE Enrichment
No data.
-
CWE-347
Improper Verification of Cryptographic Signature
Github GHSA