This release patches 2 CVEs for security teams tracking exposure across their dependency inventory.
Published 27d
AI Agents & Assistants
2 patched CVEs
This release patches 2 known CVEs
CVE-2025-31125
EPSS 83%
CVE-2026-42208
EPSS 57%
2
CVEs patched
Topics
agents
ai
ai-agents
application
chatbots
chatgpt
+7 more
genai
llm
long-term-memory
memory
memory-management
python
state-management
Summary
AI summaryHarden against SQL injection and prompt injection.
Full changelog
Mem0 Python SDK (v2.0.2)
Bug Fixes:
- Telemetry: Stitch OSS and platform PostHog identities on
MemoryClientinit so$identifyevents fire and a single user is no longer tracked as two or three disconnected personas (#5040) - Security: Harden against SQL injection and prompt injection (#4997)
New Features:
- SDK: Expose
decayonproject.update(#5062)
Improvements:
- Plugin: Hand
mem0search decisions to the agent (#4992)
Security Fixes
- Harden against SQL injection and prompt injection
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]