From fbf6b8c0db6fee3f8c0776327bad907ae178ca02 Mon Sep 17 00:00:00 2001 From: harshgupta-mem0 Date: Fri, 12 Jun 2026 19:48:13 +0530 Subject: [PATCH] fix(@mem0/community): upgrade @langchain/community to ^1.1.18 (CVE-2026-27795, CVE-2026-26019) Bumps @langchain/community from ^0.3.36 to ^1.1.18 and @langchain/core from ^0.3.42 to ^1.1.27 to resolve two SSRF CVEs in RecursiveUrlLoader. Resolves Dependabot alerts #496 and #538. --- mem0-ts/src/community/package.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/mem0-ts/src/community/package.json b/mem0-ts/src/community/package.json index 698289de9..6f16ae23c 100644 --- a/mem0-ts/src/community/package.json +++ b/mem0-ts/src/community/package.json @@ -75,8 +75,8 @@ "typescript": "5.5.4" }, "dependencies": { - "@langchain/community": "^0.3.36", - "@langchain/core": "^0.3.42", + "@langchain/community": "^1.1.18", + "@langchain/core": "^1.1.27", "axios": "^1.16.0", "mem0ai": "^2.1.8", "uuid": "^11.1.1",