Skip to content
Tools / MemMachine / Security

Security Deep Dive

MemMachine

Security posture and CVE patch evidence from tracked releases.

Back to Tool

12 critical dependency CVEs affects v0.3.9.

Audit transitive dependencies; consider upgrading or pinning replacements.

— Signed — SLSA — SBOM ✓ Security policy Weekly cadence · 7d median Active maintainer

Trust Signals — 3 of 9 Present

Evidence already collected from releases and repository metadata.

3/9 Present
Signed releases Unknown
Latest release artifact signature Latest release
SLSA provenance Unknown
Attestation predicate level Latest release
SBOM published Unknown
GitHub SBOM API Latest release
SECURITY.md Present
GitHub repository metadata Repository policy
Checked: 23d ago
Release cadence: weekly Present
7d median over recent releases Release history
Latest release: 17d ago
Maintainer active Present
Recent commit activity Repository
Last commit: 2d ago
Checksums (SHA256SUMS) Not active yet
SHA256SUMS or equivalent Release asset
Latest release: 17d ago
GitHub Actions attestation Not active yet
actions/attest-build-provenance Workflow file
Latest release: 17d ago
Signing assets Not active yet
.sig, .crt, cosign.pub, or similar Release asset
Latest release: 17d ago
3.8/10 Security Score
Dependency Exposure 103 transitive dependency CVEs found in the latest SBOM. 12 critical.

Security Score

A composite score aggregating Scorecard performance, CVE patch history, OpenSSF badge tier, and dependency vulnerability exposure. Score ≥ 7.0 is healthy; < 4.0 warrants attention.

epss

0.25 / 0.5

No EPSS data

freshness

1.00 / 1.0

2d stale

scorecard

2.00 / 4.0

⚠ Estimated — not yet collected

cve health

0.00 / 2.5

⚠ No direct scan — 12c/45h transitive CVEs

patch speed

0.50 / 0.5

⚠ Estimated — no CVE patch history

kev exposure

1.50 / 1.5

No KEV exposure

supply chain risk

-1.50 / 10.0

Risk 100.0/100

Score breakdown

schema v2

Vulnerability posture

vulnerability posture

0.0

25%

direct cves: clear cve scan: estimated

Release responsiveness

release responsiveness

10.0

5%

patch speed days: no_history

Dependency exposure

dependency exposure

0.0

10%

supply chain risk: 100.0 transitive cves: 12c/45h

Provenance trust

provenance trust

5.0

40%

scorecard score: estimated openssf badge: none

Maintainer health

maintainer health

10.0

10%

activity freshness: 2d

Operational risk

operational risk

8.5

10%

kev exposure: clear epss max: none
How is this calculated?

The six dimensions group the legacy score signals into weighted categories: direct vulnerability status, patch responsiveness, dependency exposure, provenance checks, maintainer activity, and exploitability risk. The flat component values above remain available for compatibility.

Supply Chain Risk

Risk 100.0/100
12 Transitive critical CVEs
0 KEV-transitive CVEs
47% Dependency freshness

OpenSSF Badge

OpenSSF none

Badge indicates adherence to open-source best practices.

Dependency Vulnerabilities

1773 dependencies scanned View full dependency list →

Scanning the SBOM (Software Bill of Materials) of the latest release for known vulnerabilities in transitive dependencies.

Critical

12

High

45

Medium

43

Low

3

Unknown

0

Critical 12 High 45 Medium 43 Low 3
CVE Severity KEV Dependency Affected version Cleared in release
CVE-2012-0805 critical sqlalchemy v0.3.8
CVE-2017-18342 critical pyyaml v0.3.8
CVE-2018-20060 critical urllib3 v0.3.8
CVE-2019-20477 critical pyyaml v0.3.8
CVE-2019-7164 critical sqlalchemy v0.3.8
CVE-2019-7548 critical sqlalchemy v0.3.8
CVE-2020-14343 critical pyyaml v0.3.8
CVE-2020-17446 critical asyncpg v0.3.8
CVE-2020-1747 critical pyyaml v0.3.8
CVE-2024-3829 critical qdrant-client v0.3.8
CVE-2025-14009 critical nltk v0.3.8
CVE-2026-32871 critical fastmcp v0.3.8
CVE-2013-1633 high setuptools v0.3.8
CVE-2018-18074 high requests v0.3.8
CVE-2019-11324 high urllib3 v0.3.8
CVE-2019-14751 high nltk v0.3.8
CVE-2019-18874 high psutil v0.3.8
CVE-2020-7212 high urllib3 v0.3.8
CVE-2020-7694 high uvicorn v0.3.8
CVE-2020-7695 high uvicorn v0.3.8
CVE-2021-32677 high fastapi v0.3.8
CVE-2021-33503 high urllib3 v0.3.8
CVE-2021-3828 high nltk v0.3.8
CVE-2021-3842 high nltk v0.3.8
CVE-2021-43854 high nltk v0.3.8
CVE-2022-40897 high setuptools v0.3.8
CVE-2022-40898 high wheel v0.3.8
CVE-2023-43804 high urllib3 v0.3.8
CVE-2024-24762 high fastapi v0.3.8
CVE-2024-39705 high nltk v0.3.8
CVE-2024-46488 high sqlite-vec v0.3.8
CVE-2024-6345 high setuptools v0.3.8
CVE-2025-47273 high setuptools v0.3.8
CVE-2025-66418 high urllib3 v0.3.8
CVE-2025-66471 high urllib3 v0.3.8
CVE-2025-69196 high fastmcp v0.3.8
CVE-2026-0846 high nltk v0.3.8
CVE-2026-0847 high nltk v0.3.8
CVE-2026-21441 high urllib3 v0.3.8
CVE-2026-24049 high wheel v0.3.8
CVE-2026-27124 high fastmcp v0.3.8
CVE-2026-33231 high nltk v0.3.8
CVE-2026-33236 high nltk v0.3.8
CVE-2026-42033 high axios 1.15.0 v0.3.8
CVE-2026-42035 high axios 1.15.0 v0.3.8
CVE-2026-42043 high axios 1.15.0 v0.3.8
CVE-2026-42264 high axios 1.15.0 v0.3.8
CVE-2026-42561 high python-multipart 0.0.26 v0.3.8
CVE-2026-44240 high basic-ftp 5.3.0 v0.3.8
CVE-2026-44307 high mako 1.3.11 v0.3.8
CVE-2026-44665 high fast-xml-builder 1.1.5 v0.3.8
CVE-2026-6321 high fast-uri 3.1.0 v0.3.8
CVE-2026-6322 high fast-uri 3.1.0 v0.3.8
GHSA-c2jp-c369-7pvx high fastmcp v0.3.8
GHSA-cwj3-vqpp-pmxr high openclaw 2026.4.22 v0.3.8
GHSA-r39h-4c2p-3jxp high openclaw 2026.4.22 v0.3.8
GHSA-rcfx-77hg-w2wv high fastmcp v0.3.8
CVE-2014-1829 medium requests v0.3.8
CVE-2014-1830 medium requests v0.3.8
CVE-2015-2296 medium requests v0.3.8
CVE-2016-9015 medium urllib3 v0.3.8
CVE-2018-25091 medium urllib3 v0.3.8
CVE-2019-11236 medium urllib3 v0.3.8
CVE-2020-26137 medium urllib3 v0.3.8
CVE-2021-28363 medium urllib3 v0.3.8
CVE-2021-29510 medium pydantic v0.3.8
CVE-2023-32681 medium requests v0.3.8
CVE-2023-37365 medium hnswlib v0.3.8
CVE-2023-45803 medium urllib3 v0.3.8
CVE-2024-35195 medium requests v0.3.8
CVE-2024-3772 medium pydantic v0.3.8
CVE-2024-37891 medium urllib3 v0.3.8
CVE-2024-42474 medium streamlit 1.28.0 v0.3.8
CVE-2024-47081 medium requests v0.3.8
CVE-2025-50181 medium urllib3 v0.3.8
CVE-2025-50182 medium urllib3 v0.3.8
CVE-2025-62800 medium fastmcp v0.3.8
CVE-2025-62801 medium fastmcp v0.3.8
CVE-2025-64340 medium fastmcp v0.3.8
CVE-2025-69872 medium diskcache 5.6.3 v0.3.8
CVE-2025-71176 medium pytest v0.3.8
CVE-2026-25645 medium requests v0.3.8
CVE-2026-28684 medium python-dotenv 1.0.0 v0.3.8
CVE-2026-33230 medium nltk v0.3.8
CVE-2026-33682 medium streamlit 1.28.0 v0.3.8
CVE-2026-41686 medium @anthropic-ai/sdk 0.90.0 v0.3.8
CVE-2026-42034 medium axios 1.15.0 v0.3.8
CVE-2026-42036 medium axios 1.15.0 v0.3.8
CVE-2026-42037 medium axios 1.15.0 v0.3.8
CVE-2026-42038 medium axios 1.15.0 v0.3.8
CVE-2026-42039 medium axios 1.15.0 v0.3.8
CVE-2026-42041 medium axios 1.15.0 v0.3.8
CVE-2026-42042 medium axios 1.15.0 v0.3.8
CVE-2026-42044 medium axios 1.15.0 v0.3.8
CVE-2026-42338 medium ip-address 10.1.0 v0.3.8
CVE-2026-44455 medium hono 4.12.14 v0.3.8
CVE-2026-44456 medium hono 4.12.14 v0.3.8
CVE-2026-44664 medium fast-xml-builder 1.1.5 v0.3.8
GHSA-q8ff-7ffm-m3r9 medium openclaw 2026.4.22 v0.3.8
GHSA-rf74-v2fm-23pw medium nltk v0.3.8
CVE-2024-34062 low tqdm 4.65.0 v0.3.8
CVE-2026-42040 low axios 1.15.0 v0.3.8
GHSA-8qw9-gf7w-42x5 low streamlit 1.28.0 v0.3.8

Showing 103 of 103

Beta — feedback welcome: [email protected]