Vendor
MemOS contains an authentication bypass vulnerability where unset environment variables cause the internal request middleware to fail open, granting unauthenticated remote attackers administrative access.