Skip to content

mem0

vts-v3.0.8 scope: ts Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

agents ai ai-agents application chatbots chatgpt
+7 more
genai llm long-term-memory memory memory-management python state-management

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

Upgrade @langchain/community to ^1.1.18 immediately to remediate CVE-2026-27795 and CVE-2026-26019.

Why it matters: CVE severity is high (severity 90); upgrading eliminates critical vulnerabilities affecting dependency upgrades.

Summary

AI summary

Upgrade dependencies to remediate CVE-2026-27795 and CVE-2026-26019, adding contextual OSS-to-Platform notices.

Changes in this release

Security Critical

Upgrade @langchain/community to ^1.1.18 to remediate CVE-2026-27795 and CVE-2026-26019

Upgrade @langchain/community to ^1.1.18 to remediate CVE-2026-27795 and CVE-2026-26019

Source: llm_adapter@2026-06-13

Confidence: high

Feature Low

Add contextual OSS-to-Platform notices system with disable flag MEM0_TELEMETRY=false

Add contextual OSS-to-Platform notices system with disable flag MEM0_TELEMETRY=false

Source: llm_adapter@2026-06-13

Confidence: high

Full changelog

Mem0 Node SDK (v3.0.8)

New Features:

  • Memory: Add a contextual OSS-to-Platform notices system that surfaces occasional, situation-aware messages (first run, scale/performance thresholds, slow queries, and when temporal/decay features are relevant) pointing to the corresponding Mem0 Platform capabilities; disable via MEM0_TELEMETRY=false (#5494)

Security:

  • Dependencies: Upgrade @langchain/community to ^1.1.18 to remediate CVE-2026-27795 and CVE-2026-26019 (#5510)
  • Dependencies: Resolve all open MEDIUM Dependabot alerts via pnpm overrides (#5489)

Security Fixes

  • dep: CVE-2026-27795 remediated by upgrading @langchain/community to ^1.1.18
  • dep: CVE-2026-26019 remediated by upgrading @langchain/community to ^1.1.18

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track mem0

Get notified when new releases ship.

Sign up free

About mem0

Universal memory layer for AI Agents

All releases →

Related context

Related CVEs

Beta — feedback welcome: [email protected]