CVE-2026-11330

LOW

thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash

Title source: cna
STIX 2.1

Description

A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observations/store.ts of the component Observation Content Hash Handler. This manipulation causes use of weak hash. The attack can only be executed locally. The attack's complexity is rated as high. The exploitability is described as difficult. Upgrading to version 12.0.0 is sufficient to fix this issue. Patch name: f32fda8b35e9fe9329f87da65c31149362a03f97. It is suggested to upgrade the affected component.

References (8)

Core 8
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-368870 | thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
https://vuldb.com/vuln/368870
Signature, Permissions Required signature permissions-required
VDB-368870 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/368870/cti
Third Party Advisory third-party-advisory
CVE-2026-11330 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-11330
Third Party Advisory third-party-advisory
Submit #832401 | thedotmack claude-mem v10.4.0 - Improper content hash construction - Field-boundary ambiguity
https://vuldb.com/submit/832401

Scores

CVSS v3 3.6
EPSS 0.0008
EPSS Percentile 0.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-327 CWE-328
Status published
Products (3)
thedotmack/claude-mem 11.0.0
thedotmack/claude-mem 11.0.1
thedotmack/claude-mem 12.0.0
Published Jun 05, 2026
Tracked Since Jun 05, 2026