CVE-2026-33010: mcp-memory-service CORS Wildcard + Anonymous Access Lets Any Website Read/Delete Agent Memories
TheHackerWire·high signal
Disclosed March 20, 2026 with CVSS 8.1, CVE-2026-33010 affects mcp-memory-service, a widely-used open-source memory backend for multi-agent systems. When HTTP mode is enabled with anonymous access (MCP_ALLOW_ANONYMOUS_ACCESS=true — the default 'easy setup' path), the CORS wildcard configuration allows any malicious webpage to silently read, modify, or delete all stored agent memories via cross-origin JavaScript. A second attack vector enables direct network access with no CORS involved. The combination of an insecure-by-default configuration and a multi-agent memory store makes this a high-blast-radius supply chain risk; patched in version 10.25.1.