artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue
mcp-memory-service: Missing Authentication on Document API Endpoints Allows
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection