This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
agents
ai
ai-agents
application
chatbots
chatgpt
+7 more
genai
llm
long-term-memory
memory
memory-management
python
state-management
Affected surfaces
deps
Summary
AI summaryFix Anthropic tool choice format and parsing, preserve custom metadata on memory updates, and bump esbuild for a security fix.
Full changelog
Mem0 Node SDK (v3.0.9)
Bug Fixes:
- LLMs: Fix Anthropic
tool_choiceformat — was incorrectly sent as a bare string"auto"(rejected by the API); now correctly sent as{ type: "auto" }. Also fixes tool response parsing:tool_useblocks are now parsed intotoolCallsobjects instead of throwing. Updated default model toclaude-sonnet-4-6and defaultmax_tokensto2000to match the Python provider. Addedtemperature,topP, andmaxTokenstoLLMConfigso Anthropic params can be configured (#5537) - Memory (OSS): Preserve custom metadata fields during
update()— fields such ascategory,priority, and other user-defined keys were previously dropped on update; the existing payload is now spread before applying the new data (#5480) - Client: Preserve user-defined schema keys in
createMemoryExport(#5594)
Security:
- Dependencies: Bump
esbuildto>=0.28.1across all npm packages via pnpm overrides to remediate upstream vulnerability (#5563)
Security Fixes
- dep: esbuild >=0.28.1 — remediate upstream vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]