@mastra/server is vulnerable to Missing Authorization
71
High Risk
The @mastra/server memory API skips the thread ownership check when the server uses authentication without a mapUserToResourceId callback. The resource id then uses a caller supplied value and can be undefined, so storage returns every thread. An authenticated caller can list all threads and read conversation history, messages, and working memory belonging to other resource owners. The fix applies resource scoped access and rejects authenticated requests that cannot be resolved to a resource id.
You are affected if you are using a version that falls within the vulnerable range and you configure server authentication without a mapUserToResourceId callback.
@mastra/server is vulnerable to Missing Authorization in versions 1.1.0 - 1.63.0.
Upgrade the @mastra/server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.