PatchSiren

VoltAgent CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH VoltAgent CVE published 2026-08-28

CVE-2026-82283

CVE-2026-82283 debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T20:20:19.683Z and has not been modified since then. VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. This vulnerability allows attackers to read, modify, and delete arbitrary conversations and mess [truncated]

LOW VoltAgent CVE published 2026-06-28

CVE-2026-13511

CVE-2026-13511 is an improper authorization vulnerability in the Memory REST API of VoltAgent, affecting versions up to 2.1.17. The vulnerability is located in the handleGetMemoryConversation function within the memory.handlers.ts file. Exploitation requires a manipulated conversationId argument and is characterized by high complexity and difficulty. The attack can be performed remotely, and a public expl [truncated]