gitsafehub
github.com/jnmetacode/mem0 ↗

jnmetacode/mem0

scanned 2026-08-08 · git 72e2c5c
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets13Vulnerable dependencies769Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 13 found · 4 serious

API keys, passwords or tokens committed into the repo.

  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs/platform/features/async-mode-default-change.mdx:110
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs/platform/features/expiration-date.mdx:72
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs/platform/features/memory-export.mdx:144
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs/platform/features/timestamp.mdx:85
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    docs/docs.json:774
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    embedchain/docs/mint.json:254
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    embedchain/embedchain/telemetry/posthog.py:14
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    embedchain/tests/telemetry/test_posthog.py:13
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    examples/yt-assistant-chrome/src/background.js:21
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    examples/yt-assistant-chrome/src/background.js:61
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    mem0-ts/src/client/telemetry.ts:11
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    mem0-ts/src/oss/src/utils/telemetry.ts:14
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    mem0/memory/telemetry.py:12
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 769 found · 23 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2023-6572 Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
    embedchain/embedchain/deployment/gradio.app/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6572). Fix: Update that package to its patched version.
  • Serious CVE-2024-1728 Gradio allows users to access arbitrary files
    embedchain/embedchain/deployment/gradio.app/requirements.txt
    A package you depend on has a known security hole (CVE-2024-1728). Fix: Update that package to its patched version.
  • Serious CVE-2025-23042 Gradio Blocked Path ACL Bypass Vulnerability
    embedchain/embedchain/deployment/gradio.app/requirements.txt
    A package you depend on has a known security hole (CVE-2025-23042). Fix: Update that package to its patched version.
  • Serious CVE-2024-23731 Code execution in Embedchain
    embedchain/examples/chainlit/requirements.txt
    A package you depend on has a known security hole (CVE-2024-23731). Fix: Update that package to its patched version.
  • Serious CVE-2024-23731 Code execution in Embedchain
    embedchain/examples/discord_bot/requirements.txt
    A package you depend on has a known security hole (CVE-2024-23731). Fix: Update that package to its patched version.
  • Serious CVE-2024-23731 Code execution in Embedchain
    embedchain/examples/full_stack/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-23731). Fix: Update that package to its patched version.
  • Serious CVE-2025-29927 nextjs: Authorization Bypass in Next.js Middleware
    embedchain/examples/full_stack/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2025-29927). Fix: Update that package to its patched version.
  • Serious CVE-2024-23731 Code execution in Embedchain
    embedchain/examples/rest-api/requirements.txt
    A package you depend on has a known security hole (CVE-2024-23731). Fix: Update that package to its patched version.
  • Serious CVE-2026-27962 authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerability
    embedchain/poetry.lock
    A package you depend on has a known security hole (CVE-2026-27962). Fix: Update that package to its patched version.
  • Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
    embedchain/poetry.lock
    A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
  • Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
    embedchain/poetry.lock
    A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
  • Serious CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...
    embedchain/poetry.lock
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Serious CVE-2025-7783 form-data: Unsafe random function in form-data
    mem0-ts/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
    mem0-ts/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious CVE-2025-7783 form-data: Unsafe random function in form-data
    openmemory/ui/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious CVE-2025-55182 next: React Server Components: Pre-authentication remote code execution via unsafe deserialization
    openmemory/ui/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-55182). Fix: Update that package to its patched version.
  • Serious CVE-2026-27962 authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerability
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-27962). Fix: Update that package to its patched version.
  • Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
  • Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
  • Serious CVE-2026-35030 litellm: LiteLLM: Authentication bypass and privilege escalation via OIDC userinfo cache key collision
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-35030). Fix: Update that package to its patched version.
  • Serious CVE-2026-49468 litellm: LiteLLM: Authentication Bypass via Host Header Injection
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-49468). Fix: Update that package to its patched version.
  • Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
  • Serious CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-1561 gradio vulnerable to Path Traversal
    embedchain/embedchain/deployment/gradio.app/requirements.txt
    A package you depend on has a known security hole (CVE-2024-1561). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-2206 gradio Server-Side Request Forgery vulnerability
    embedchain/embedchain/deployment/gradio.app/requirements.txt
    A package you depend on has a known security hole (CVE-2024-2206). Fix: Update that package to its patched version.
… 744 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner timed out

Your dependencies cross-checked against the OSV vulnerability database.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OSV-Scanner v1.9.2 · Apache-2.0

error: timeout after 120s

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog couldn’t run

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:ERROR: Error while scanning. Received 'utf-8' codec can't decode byte 0xff in position 0: invalid start byte Traceback (

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.