Total Recall

What is Total Recall?

Total Recall is the name Pluto Security Research gave to a disclosure of two vulnerabilities in mcp-memory-service, a persistent-memory service used by AI assistants. The vulnerabilities could allow an external, attacker-controlled webpage to read, modify, or delete the persistent memory of an AI agent, without requiring a jailbreak or injected instruction.

What Total Recall demonstrated

The research showed that an agent’s persistence layer, the system responsible for remembering context across sessions, could be manipulated by something as passive as a webpage a user visited, entirely separately from the model’s own behavior. The agent itself performed exactly as designed throughout; the issue was in how memory was written and validated, rather than in the model’s prompt-handling behavior.

The two vulnerabilities were

  • CVE-2026-33010, a wildcard CORS misconfiguration enabling cross-origin memory theft
  • CVE-2026-29787, a system information disclosure through the service’s health endpoint

Why the finding mattered beyond the two CVEs themselves

Most published AI security research at the time this ran focused on manipulating a model within a single conversation. Total Recall demonstrated a different, arguably more significant risk: an attack that persists across every future session until detected or remediated, without requiring the attacker to be present or interacting with the target at the time of exploitation. This represents a different threat model from live prompt injection attacks and illustrates the broader class of attacks targeting persistent agent memory.

Why it matters beyond the specific finding

Total Recall is the canonical example behind the broader security problem known as agent memory poisoning: an attack class targeting an AI agent’s persistent memory rather than a single session’s context.

FAQs

1. What are the exact CVE numbers for Total Recall?

CVE-2026-33010 (wildcard CORS enabling cross-origin memory theft, CVSS 8.1) and CVE-2026-29787 (system information disclosure via a health endpoint, CVSS 5.3), both in mcp-memory-service.

2. What products or platforms were affected?

See the full Total Recall research write-up for the specific affected systems and versions.

3. Has this been fixed?

See the full research write-up for disclosure timeline and remediation status.

4. Is this related to prompt injection?

They are related but distinct. Total Recall did not require an injected instruction; the vulnerability affected the memory-persistence layer handling external content, independent of the model’s prompt-handling behavior.

5. Why is it called Total Recall?

The name reflects the finding’s core capability: an external party gaining the ability to rewrite what an agent “recalls” about its own past interactions.