VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-85093

CVE-2026-85093: Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retriev

Published Sep 3, 2026 CVSS 7.1

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.

Affected AI Products

cursor
Get the weekly digest. Every Monday: top AI security stories of the week. Free.