CVE-2026-106037: Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/removeall and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount attacker-described segments.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Any Mooncake Store REST service instance reachable by an attacker is exposed, because the service binds to 0.0.0.0 and does not require authentication on any route. The affected versions are through 0.3.13.post1.
What does an attacker need to exploit it?
An attacker only needs network access to the Store REST service. No authentication, privileges, or user interaction are required.
What could an unauthenticated attacker do?
An attacker can use endpoints including /api/get, /api/put, /api/remove_all, and /api/mount to read cached KV data containing user prompts, inject or delete objects, and mount attacker-described segments.