Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
Vulnerability Description
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check in src/memos/api/middleware/auth.py fails open: os.getenv("INTERNAL_SERVICE_SECRET") returns None and a request omitting the X-Internal-Service header also yields None, so the comparison None == None evaluates true. The request is then treated as a trusted internal principal and granted scopes: ["all"]. As a result, an unauthenticated remote attacker can reach the admin API-key management endpoints to mint API keys for any user, enumerate keys, revoke keys, and generate a master key for persistent privileged access, as well as all data endpoints.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不充分的比较
Vulnerability Title
OpenMem MemOS 处理逻辑错误漏洞
Vulnerability Description
OpenMem MemOS是OpenMem组织的一款融合机器学习能力的操作系统。 OpenMem MemOS 2.0.30及之前版本存在处理逻辑错误漏洞,该漏洞源于is_internal_request()函数对INTERNAL_SERVICE_SECRET环境变量验证不当,导致未设置时认证检查失效,未认证的远程攻击者可访问管理API密钥接口,创建、枚举、撤销API密钥并生成主密钥,从而获得持久特权访问权限及所有数据端点访问权限。
CVSS Information
N/A
Vulnerability Type
N/A