This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
ReleasePort's take
Moderate signalUpgrade @langchain/community to ^1.1.18 immediately to remediate CVE-2026-27795 and CVE-2026-26019.
Why it matters: CVE severity is high (severity 90); upgrading eliminates critical vulnerabilities affecting dependency upgrades.
Summary
AI summaryUpgrade dependencies to remediate CVE-2026-27795 and CVE-2026-26019, adding contextual OSS-to-Platform notices.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Upgrade @langchain/community to ^1.1.18 to remediate CVE-2026-27795 and CVE-2026-26019 Upgrade @langchain/community to ^1.1.18 to remediate CVE-2026-27795 and CVE-2026-26019 Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Feature | Low |
Add contextual OSS-to-Platform notices system with disable flag MEM0_TELEMETRY=false Add contextual OSS-to-Platform notices system with disable flag MEM0_TELEMETRY=false Source: llm_adapter@2026-06-13 Confidence: high |
— |
Full changelog
Mem0 Node SDK (v3.0.8)
New Features:
- Memory: Add a contextual OSS-to-Platform notices system that surfaces occasional, situation-aware messages (first run, scale/performance thresholds, slow queries, and when temporal/decay features are relevant) pointing to the corresponding Mem0 Platform capabilities; disable via
MEM0_TELEMETRY=false(#5494)
Security:
Security Fixes
- dep: CVE-2026-27795 remediated by upgrading @langchain/community to ^1.1.18
- dep: CVE-2026-26019 remediated by upgrading @langchain/community to ^1.1.18
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]