PatchSiren

mastra-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mastra-ai CVE published 2026-08-28

CVE-2026-82273

CVE-2026-82273 is a high-severity vulnerability in Mastra, a product from an unknown vendor. The vulnerability allows authenticated attackers to bypass authentication and enumerate all threads via a GET request to /api/memory/threads, potentially reading conversation history and metadata of other resource owners. This could lead to unauthorized access to sensitive information. Defenders responsible for Ma [truncated]