This release includes 1 security fix for security teams reviewing exposed deployments.
Published 3mo
Relational Databases
✓ No known CVEs patched
This release patches 1 known CVE
Topics
claude-code
claude-code-plugin
context
full-text-search
memory
plugin
+1 more
sqlite
Affected surfaces
rce_ssrf
Summary
AI summarySQL injection vulnerabilities fixed in get_table_count() and get_stats().
Full changelog
Fixed
--projectflag now works as both a bare flag (uses cwd) and with a path argument- BM25 relevance display no longer shows
0.0— replaced with rank-basedMatch #N - Windows path hashing mismatch between MSYS/Git Bash (
/c/Users/...) and native Windows (C:\Users\...) paths; added case-insensitive normalization - Stop hook no longer references undefined
$CLAUDE_PLUGIN_ROOTand$CLAUDE_SESSION_IDenvironment variables - SQL injection vector in
get_table_count()andget_stats()via table name validation
Added
--decisions,--problems,--technologies, and--outcomeCLI arguments todb_save.py
Security Fixes
- Fixed SQL injection vector in get_table_count() and get_stats() via table name validation
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About ErebusEnigma/context-memory
Persistent, searchable context storage across Claude Code sessions using SQLite FTS5. Save sessions with AI-generated summaries, two-tier full-text search, checkpoint recovery, and a web dashboard.
Related context
Related tools
Beta — feedback welcome: [email protected]