{"id":"CVE-2026-7597","aliases":["GHSA-xqxw-r767-67m7","PYSEC-2026-2636"],"url":"https://o3.security/vulnerability/CVE-2026-7597","summary":"mem0ai mem0 faiss.py pickle.dump deserialization","details":"A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.","published":"2026-05-01T21:15:11.399Z","modified":"2026-08-07T11:51:33.709122998Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mem0ai","fixedVersion":"2.0.0b2"}],"fix":{"url":"https://github.com/mem0ai/mem0/commit/62dca096f9236010ca15fea9ba369ba740b86b7a","label":"mem0ai/mem0@62dca09"},"references":[{"type":"WEB","url":"https://github.com/mem0ai/mem0/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7597.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7597"},{"type":"ADVISORY","url":"https://vuldb.com/submit/805562"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/360550"},{"type":"REPORT","url":"https://github.com/mem0ai/mem0/issues/3778"},{"type":"REPORT","url":"https://vuldb.com/vuln/360550/cti"},{"type":"FIX","url":"https://github.com/mem0ai/mem0/commit/62dca096f9236010ca15fea9ba369ba740b86b7a"},{"type":"FIX","url":"https://github.com/mem0ai/mem0/pull/4833"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:33.709122998Z"}}