CVE-2026-44830

Source
https://cve.org/CVERecord?id=CVE-2026-44830
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44830.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44830
Aliases
  • GHSA-crr4-xrj9-ww8g
Published
2026-05-27T14:19:55.126Z
Modified
2026-07-15T01:49:18.920367465Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Empty API_TOKEN disables authentication on network-reachable HTTP/SSE transport
Details

Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when APITOKEN is unset or empty, the BearerTokenAuthMiddleware bypasses authentication for all HTTP requests. Combined with the default 0.0.0.0 host binding and CORS alloworigins=[""], operators following the Docker setup without explicitly setting API_TOKEN expose the full Knowledge-Graph read/write API to any LAN-reachable client. An attacker on the same network can read, write, or delete all memory entries — including system://boot and core:// URIs that auto-load into downstream agent sessions, enabling persistent prompt-injection. This vulnerability is fixed in 2.4.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44830.json"
}
References

Affected packages

Git / github.com/dataojitori/nocturne_memory

Affected ranges

Type
GIT
Repo
https://github.com/dataojitori/nocturne_memory
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.4.1"
        }
    ]
}

Affected versions

1.*
1.3.0
1.3.1
1.3.2
2.*
2.0.0
2.0.1
2.1.1
2.2.0
2.3.0
2.4.0
v0.*
v0.9.0-legacy
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44830.json"