Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-11330— thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash

Quick assessment

Affected
thedotmack claude-mem
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Claude-Mem是Alex Newman个人开发者的一个AI开发助手长期记忆系统。 Claude-Mem 11.0.1及之前版本存在安全漏洞,该漏洞源于Observation Content Hash Handler组件中src/services/sqlite/observations/store.ts文件的computeObservationContentHash函数使用弱哈希。

CVSS 3.6 · Low EPSS 0.07% · P0

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 3

VendorProduct Version RangeStatus
thedotmack claude-mem 11.0.0 affected
11.0.1 affected
12.0.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-11330

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
Source: CVE Program / CVE List V5
Vulnerability Description
A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observations/store.ts of the component Observation Content Hash Handler. This manipulation causes use of weak hash. The attack can only be executed locally. The attack's complexity is rated as high. The exploitability is described as difficult. Upgrading to version 12.0.0 is sufficient to fix this issue. Patch name: f32fda8b35e9fe9329f87da65c31149362a03f97. It is suggested to upgrade the affected component.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
可逆的单向哈希
Source: CVE Program / CVE List V5
Vulnerability Title
Claude-Mem 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Claude-Mem是Alex Newman个人开发者的一个AI开发助手长期记忆系统。 Claude-Mem 11.0.1及之前版本存在安全漏洞,该漏洞源于Observation Content Hash Handler组件中src/services/sqlite/observations/store.ts文件的computeObservationContentHash函数使用弱哈希。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
thedotmack claude-mem 11.0.0 cpe:2.3:a:thedotmack:claude-mem:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-11330

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-11330

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-11330 (2)

Security Blog Posts for CVE-2026-11330 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-11330

No comments yet


Leave a comment