GHSA-5gvr-v6qv-h5mm

Suggest an improvement
Source
https://github.com/advisories/GHSA-5gvr-v6qv-h5mm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5gvr-v6qv-h5mm/GHSA-5gvr-v6qv-h5mm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5gvr-v6qv-h5mm
Aliases
Published
2026-06-05T15:32:23Z
Modified
2026-07-17T17:11:40Z
Severity
  • 3.6 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
claude-mem: The computeObservationContentHash Function is Vulnerable to Hash Collision
Details

A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observations/store.ts of the component Observation Content Hash Handler. This manipulation causes use of weak hash. The attack can only be executed locally. The attack's complexity is rated as high. The exploitability is described as difficult. Upgrading to version 12.0.0 is sufficient to fix this issue. Patch name: f32fda8b35e9fe9329f87da65c31149362a03f97. It is suggested to upgrade the affected component.

Database specific
{
    "cwe_ids":  [
        "CWE-327"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-17T16:53:30Z",
    "nvd_published_at":  "2026-06-05T14:16:35Z",
    "severity":  "LOW"
}
References

Affected packages

npm / claude-mem

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5gvr-v6qv-h5mm/GHSA-5gvr-v6qv-h5mm.json"