Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for Engram by get-engram

Pod holds 10 of 10 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to Engram by get-engram.

Most discussed

bug: ChatGPT MCP tool call blocked — Engram tools fail to execute

Bug

When using Engram as an MCP connector in ChatGPT (Settings > Apps > Developer mode), tool calls to Engram are blocked. ChatGPT reports: "I also tried to pass your request to Engram, but the tool call was blocked, so I can't confirm that anything was saved there."

Screenshot

User asked: "Engram can you remember everything I've said in my chatgpt"

ChatGPT attempted to call an Engram tool but it was blocked. The response fell back to a generic explanation instead of using the MCP…

Read the thread · 2026-07-08 · closed · outside contributor · 3 comments

MCP tools stay callable after the access token expires, with no re-auth path surfaced

Reported from a live session 2026-09-02: the MCP access token expired mid-write, the tool schemas remained loaded and callable, writes failed, and nothing offered a way to re-authenticate. Workaround was to write through the engram CLI instead, which authenticates off the long-lived API key in ~/.engram/config.json.

This is NOT the revocation bug from #389

Checked before assuming:

chain revocations since #389 deployed (2026-08-31 17:34Z):   0
all time:…

[Read the thread](https://github.com/get-engram/engram/issues/399) · 2026-09-02 · open · outside contributor · 1 comment

### [P3] /mcp POST handler returns raw internal error message to the client, bypassing the scrubbed-500 policy

## Summary
(Reported by two dimensions — merged.) The global `onError` was deliberately hardened to return only a generic message and never `err.message`, but the earlier `/mcp` catch runs first for the MCP path and echoes the raw exception text.

## Impact / Attack scenario
An authenticated caller (valid free account + key) sends malformed MCP JSON-RPC to `POST /mcp` to provoke transport/SDK exceptions; the response body returns the underlying error string (D1 error fragments, internal…

[Read the thread](https://github.com/get-engram/engram/issues/458) · 2026-09-21 · open · outside contributor · 0 comments

### [P1] append_messages fans out to Workers AI embeddings + Vectorize/R2 writes proportional to content size, but every quota is blind to it

## Summary
Embedding/Vectorize/R2 cost scales with **content size** (chunk count), but the three gates all count the wrong unit: storage cap counts messages, the rate limiter counts requests (1 token each), and free tier has no monthly velocity cap. A single free key can burn unmetered Workers AI Neurons.

## Impact / Attack scenario
Ceiling inputs: MAX_MESSAGE_CONTENT_CHARS=100_000, MAX_CHARS≈1920/chunk. One 100k-char message ⇒ ~53 chunks ⇒ 53 embeddings + 53 Vectorize upserts + an R2 put —…

[Read the thread](https://github.com/get-engram/engram/issues/445) · 2026-09-21 · open · outside contributor · 0 comments

### [P1] Unauthenticated service-role createUser enables account pre-hijacking and auth-table abuse

## Summary
A public `"use server"` action creates auto-confirmed Supabase auth users with the **service-role** key, no auth, no captcha, no rate limit — and swallows "already registered" as success. This is both an account pre-hijacking primitive and an unauthenticated auth-table abuse vector.

## Impact / Attack scenario
1. **Pre-hijacking:** Attacker calls `createUser(victim@corp.com, attacker_password)`. The service-role admin API creates an AUTO-CONFIRMED `auth.users` row (bypassing email…

[Read the thread](https://github.com/get-engram/engram/issues/444) · 2026-09-21 · open · outside contributor · 0 comments

### [P1] Stripe customer takeover: unverified email + email-only customer resolution binds another org's Stripe customer to the attacker

## Summary
`createOrGetCustomer` resolves a Stripe customer by **email only** and reuses it with no ownership check, and the org email that drives it is attacker-controlled and unverified (`PATCH /api/account` sets it with no confirmation). An attacker can claim a victim's Stripe customer and open its billing portal.

## Impact / Attack scenario
Precondition: the victim changed their Engram email at some point (old@x.com → new@x.com). `PATCH /api/account` never updates the Stripe customer, so…

[Read the thread](https://github.com/get-engram/engram/issues/443) · 2026-09-21 · open · outside contributor · 0 comments

### [P1] OAuth refresh-token reuse detection revokes only refresh tokens, leaving stolen access tokens live for up to 1h

## Summary
The one mechanism designed to contain refresh-token theft — reuse detection — fails to cut live sessions. On detecting reuse it calls `revokeRefreshTokenChain`, which only revokes refresh tokens; the already-minted access token keeps working because `getAccessTokenWithOrg` validates on `expires_at` only (there is no `revoked_at` on access tokens).

## Impact / Attack scenario
Attacker steals refresh token RT0, exchanges it for access token AT_evil (1h TTL) + RT1; server rotates…

[Read the thread](https://github.com/get-engram/engram/issues/442) · 2026-09-21 · open · outside contributor · 0 comments

### [P0] Team member escalates to org owner by minting a null-seat API key (POST /api/keys) + missing owner RBAC floor on key/billing/privacy routes

## Summary
Any org member (or a leaked member key) can mint an **owner-equivalent** API key and take over the entire organization. Owner-only actions are gated by `if (auth.seatId) return 403` — a NULL `seat_id` means owner. `POST /api/keys` mints keys via `insertApiKey`, which **never sets `seat_id`**, so every key it creates is a null-seat (owner) credential, and the route has no owner guard. The same missing `ownerOnly` floor also lets any member revoke other members'/the owner's keys, open…

[Read the thread](https://github.com/get-engram/engram/issues/441) · 2026-09-21 · open · outside contributor · 0 comments

## Most recent

### Security remediation: 8-dimension adversarial review (Sept 2026) — close the convention-not-construction gaps

## Posture

This epic tracks remediation of the September 2026 8-dimension adversarial security review (authz/tenancy, OAuth/MCP, web/Supabase, billing/Stripe, injection/SSRF, secrets/crypto/logging, DoS/abuse, infra/headers/supply-chain).

Building on the prior backend audit ("architecturally sound, ~80% enterprise-grade, invariants enforced by convention not construction"): that verdict holds and this review shows exactly what "by convention" costs. The data plane is genuinely well-scoped —…

[Read the thread](https://github.com/get-engram/engram/issues/440) · 2026-09-21 · open · outside contributor · 0 comments

### fix: GET /mcp hangs causing 85% scriptThrewException crash rate

## Problem

The Worker has an 85% error rate — ~43,000 `scriptThrewException` per day. All errors are:

> The Workers runtime canceled this request because it detected that your Worker's code had hung and would never generate a response.

Every crash is a `GET /mcp` with `Accept: text/event-stream` from MCP clients (Claude Code, etc.) attempting SSE streaming. The `app.all("/mcp", ...)` handler passes these to `WebStandardStreamableHTTPServerTransport.handleRequest()` which hangs forever…

[Read the thread](https://github.com/get-engram/engram/issues/240) · 2026-07-12 · closed · outside contributor · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/get-engram/engram/issues).