This release includes 1 security fix for security teams reviewing exposed deployments.
Published 29d
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
agents
ai
ai-agents
application
chatbots
chatgpt
+7 more
genai
llm
long-term-memory
memory
memory-management
python
state-management
Affected surfaces
deps
Summary
AI summaryBump undici dependency to >=6.27.0 to remediate CVE-2026-12151.
Full changelog
Mem0 Node SDK (v3.0.12)
New Features:
- Client: Add
expirationDatetoAddMemoryOptions,update(), and theMemoryinterface; addshowExpiredtoSearchMemoryOptionsandGetAllMemoryOptions(#5874) - LLMs: Add
MiniMaxLLMprovider backed by the OpenAI-compatible MiniMax API (api.minimax.io/v1, default modelMiniMax-M2.7) (#5858) - LLMs: Add
LiteLLMprovider for routing requests through a local or hosted LiteLLM proxy (#5830) - Vector Stores: Add
connectionStringandssloptions to the PGVector config, allowing connection via URI instead of individual host/user/password/port fields (#5789)
Bug Fixes:
- Memory (OSS): Validate and trim entity IDs (
userId,agentId,runId) indeleteAll()viavalidateAndTrimEntityId(#5735) - Vector Stores: Use nullish coalescing for
hashand timestamps in the Redisinsert()andupdate()paths so entity payloads that omit those fields no longer crash (#5860)
Security:
- Dependencies: Bump
undicito>=6.27.0via pnpm override to remediate CVE-2026-12151 (#5861)
Security Fixes
- CVE-2026-12151 — Bump undici to >=6.27.0 via pnpm override
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]