Skip to content

n24q02m/mnemo-mcp

v1.8.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-coding ai-memory claude claude-code cursor
+8 more
docker hybrid-search mcp mcp-server model-context-protocol python rclone sqlite

Affected surfaces

rce_ssrf breaking_upgrade

Summary

AI summary

Fix SQL injection vulnerability in vector table creation.

Full changelog

v1.8.0 (2026-03-17)

This release is published under the MIT License.

Bug Fixes

  • Add missing error test in server embedding initialization (#203, 0eb3ef5)

  • Add missing OSError test for chmod in token store (#199, 8d52eed)

  • Disable mise runtime updates in Renovate (7f99704)

  • Fix Potential Command Injection in subprocess.run (#204, c1a8012)

  • Fix SQL injection vulnerability in vector table creation (#208, 7a95b37)

  • Remove mcp-name entry from README (dfe85d7)

  • ci: Use pull_request_target for jobs requiring secrets (823944a)

  • deps: Update dependency qwen3-embed to >=1.4.3 (#188, bad4d15)

Chores

  • Add glama.json for Glama directory listing (6bdc37d)

  • Standardize repo files across MCP server portfolio (ce4a6b7)

  • deps: Lock file maintenance (#190, b26ab14)

  • deps: Update actions/download-artifact digest to 3e5f45b (#187, 32e0d32)

  • deps: Update astral-sh/setup-uv digest to 37802ad (#194, 2c0b989)

  • deps: Update dawidd6/action-send-mail action to v15 (#209, ce2b5a5)

Code Style

Documentation

  • Add v1.8-v1.9 design spec (b19ed64)

Features

  • Add better-telegram-mcp to Also by section and mcp-name (5aa65f0)

  • Add Glama.ai badge to README (fb9981f)

  • Add Jina AI embedding priority and dual-backend reranker (02f02cb)

  • Add knowledge graph, importance scoring, archive, and dedup (57c44fb)

  • Offload blocking SQLite I/O to thread in sync_full (#202, e34c2f8)

  • Testing improvement] Add test for invalid JSON token in setup_sync (#200, e683697)

  • Wire intelligence features into server (graph, importance, archive, consolidate) (351475c)


Detailed Changes: v1.7.0...v1.8.0

Security Fixes

  • Fix SQL injection vulnerability in vector table creation

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track n24q02m/mnemo-mcp

Get notified when new releases ship.

Sign up free

About n24q02m/mnemo-mcp

Persistent AI memory with SQLite hybrid search (FTS5 + semantic). Built-in Qwen3 embedding, rclone sync across machines. Zero config, no cloud, no limits.

All releases →

Beta — feedback welcome: [email protected]