CVE-2026-82273
Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read conversation history and metadata of other resource owners.
Açıklama ve Etki
Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read conversation history and metadata of other resource owners.
Referanslar
- https://github.com/mastra-ai/mastra
- https://github.com/mastra-ai/mastra/blob/b7e66f0c478a227985e0062794ef058c3714fabf/packages/server/src/server/handlers/utils.ts
- https://github.com/mastra-ai/mastra/issues/18911
- https://www.vulncheck.com/advisories/mastra-memory-api-thread-ownership-check-is-a-no-op-when-mapusertoresourceid-is-unset
Güvenli Doğrulama Notu
Bu sayfa saldırı gerçekleştiren payload'lar çalıştırmaz. Doğrulama; etkilenen ürün/sürümün envanterden kontrol edilmesi, üretici güvenlik duyurusunun incelenmesi ve güncellemenin uygulanması üzerinden yapılmalıdır.