CVE-2026-13511

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a manipulation of the argument conversationId can lead to improper authorization. The attack may be performed from remote. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

28 Jun 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-28 23:16

Updated : 2026-06-29 14:16


NVD link : CVE-2026-13511

Mitre link : CVE-2026-13511

CVE.ORG link : CVE-2026-13511


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization