mcp-memory-service is vulnerable to Cross-site Scripting (XSS)
50
Medium Risk
Affected versions of this package render the OAuth redirect URL into HTML and JavaScript without escaping or scheme filtering. A registered redirect URI containing crafted HTML or a script-capable scheme can break out of the response and run code in the user's browser.
You are affected if you are using a version that falls within the vulnerable range.
mcp-memory-service is vulnerable to Cross-site Scripting (XSS) in versions 8.24.0 - 10.39.1.
Upgrade the mcp-memory-service library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant