{"id":"CVE-2026-85093","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-85093","summary":"Cheshire Cat AI Memory Collection Endpoint Information Disclosure","details":"Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.","published":"2026-09-03T01:04:45.860Z","modified":"2026-09-03T11:46:05.045563436Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85093.json"},{"type":"PACKAGE","url":"https://github.com/cheshire-cat-ai/core"},{"type":"ARTICLE","url":"https://github.com/cheshire-cat-ai/core/blob/1.9.2/core/cat/looking_glass/stray_cat.py"},{"type":"ARTICLE","url":"https://github.com/cheshire-cat-ai/core/blob/1.9.2/core/cat/routes/memory/points.py#L350"},{"type":"REPORT","url":"https://github.com/cheshire-cat-ai/core/issues/1136"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85093"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/cheshire-cat-ai-memory-collection-endpoint-information-disclosure"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T11:46:05.045563436Z"}}