This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
agents
ai
ai-agents
application
chatbots
chatgpt
+7 more
genai
llm
long-term-memory
memory
memory-management
python
state-management
Affected surfaces
deps
Summary
AI summaryUpdates Mem0 Node SDK, OSS, and v3.0.10 across a mixed release.
Full changelog
Mem0 Node SDK (v3.0.10)
- Memory (OSS): Guard against malformed
image_urlentries inparseVisionMessagesto prevent crashes (#5631) - Memory (OSS): Return
attributedTofromget(),search(), andgetAll()(#5675) - Memory (OSS): Preserve message roles in the extraction input so assistant facts aren't attributed to the user (#5643)
- Memory (OSS): Reject empty or blank messages in
Memory.add()to prevent hallucinated memories (#5545) - Memory (OSS): Check
message.roleinstead ofcontentwhen detecting system messages (#3921) - LLMs: Honor the configured
baseURLinAnthropicLLM(#5740) - Client: Preserve
customCategoriesnames through key conversion (#5741) - Client: Prevent hallucinated memories on an empty messages payload (#5613)
- Client: Preserve user metadata keys across the case-conversion round-trip (#5515)
Security:
- Dependencies: Upgrade
form-datato>=4.0.6across pnpm workspaces to remediate CVE-2026-12143 (#5618)
Security Fixes
- dep: CVE-2026-12143 — upgrade form-data to >=4.0.6 across pnpm workspaces
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]