CVE-2026-54519 | vmDeshpande AI Agent Automation up to 0.9.0 Memory Controller memory.controller.js listMemories/deleteMemory/clearAgentMemory agentId/memory_id access control
A vulnerability has been found in vmDeshpande AI Agent Automation up to 0.9.0 and classified as critical. Impacted is the function listMemories/deleteMemory/clearAgentMemory of the file backend/src/controllers/memory.controller.js of the component Memory Controller. The manipulation of the argument agentId/memory_id leads to improper access controls.
This vulnerability is documented as CVE-2026-54519. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More