mentat (disabled)
Install command:
brew install mentatCoding assistant that leverages GPT-4 to write code
License: Apache-2.0
Development: Pull requests
Formula JSON API: /api/formula/mentat.json
Formula code: mentat.rb on GitHub
Bottle (binary package) installation support provided for:
| macOS on Apple Silicon |
tahoe | ✅ |
|---|---|---|
| sequoia | ✅ | |
| sonoma | ✅ | |
| macOS on Intel |
sonoma | ✅ |
| Linux | ARM64 | ✅ |
| x86_64 | ✅ | |
Current versions:
| stable | ✅ | 1.0.8 |
Revision: 4
Depends on:
| certifi | 2026.7.22 | Mozilla CA bundle for Python |
| numpy | 2.5.2 | Package for scientific computing with Python |
| pillow | 12.3.0 | Friendly PIL fork (Python Imaging Library) |
| python@3.14 | 3.14.7 | Interpreted, interactive, object-oriented programming language |
| rpds-py | 2026.6.3 | Python bindings to Rust's persistent data structures |
Depends on when building from source:
| rust | 1.98.0 | Safe, concurrent, practical language |
Known vulnerabilities in the current version:
| GHSA-2mqj-m65w-jghx (high) | Untrusted search path under some conditions on Windows allows arbitrary code execution |
| GHSA-h5c8-rqwp-cp95 (medium) | Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter |
| GHSA-g7vv-2v7x-gj9p (low) | tqdm CLI arguments injection attack |
| GHSA-h75v-3vvj-5mfj (medium) | Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter |
| GHSA-g92j-qhmh-64v2 (low) | Sentry's Python SDK unintentionally exposes environment variables to subprocesses |
| GHSA-gmj6-6f8f-6699 (high) | Jinja has a sandbox breakout through malicious filenames |
| GHSA-q2x7-8rv6-6q7h (high) | Jinja has a sandbox breakout through indirect reference to format method |
| GHSA-cpwx-vrp4-4pq7 | Jinja2 vulnerable to sandbox breakout through attr filter selecting format method |
| GHSA-38jv-5279-wg99 (high) | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) |
| GHSA-gc5v-m9x4-r6x2 (medium) | Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function |
| GHSA-mf9w-mj56-hr94 (medium) | python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rena... |
| GHSA-rpm5-65cw-6hj4 (high) | GitPython has Command Injection via Git options bypass |
| GHSA-x2qx-6953-8485 (high) | GitPython: Unsafe option check validates multi_options before shlex.split transformation |
| GHSA-7545-fcxq-7j24 (high) | GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and ... |
| GHSA-v87r-6q3f-2j67 (high) | GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath |
| GHSA-qccp-gfcp-xxvc (medium) | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects |
| GHSA-mf9v-mfxr-j63j (high) | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API |
| GHSA-5239-wwwm-4pmq (low) | Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching |
| GHSA-65pc-fj4g-8rjx (medium) | Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ... |
| GHSA-rwj8-pgh3-r573 (high) | GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL |
| GHSA-956x-8gvw-wg5v (high) | GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, an... |
| GHSA-2f96-g7mh-g2hx (high) | GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blo... |
| GHSA-mv93-w799-cj2w (high) | GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, ... |
| GHSA-3rp5-jjmw-4wv2 (high) | GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand... |
| GHSA-539m-9xh6-q6rr (medium) | GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, ... |
| GHSA-3f7w-8rr8-f37f (high) | GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enab... |
| GHSA-p538-c434-8v24 (medium) | GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Co... |
| GHSA-94p4-4cq8-9g67 (high) | GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incompl... |
| GHSA-6p8h-3wgx-97gf (high) | GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary comma... |
| GHSA-fjr4-x663-mwxc (high) | GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (ke... |
| GHSA-r9mr-m37c-5fr3 (high) | GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enable... |
| GHSA-hh9p-6wh2-4mfc (medium) | GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() |
| GHSA-9rj7-rf2p-w77r (high) | GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via -... |
| GHSA-4gmw-gg2m-w46p (high) | GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enab... |
| GHSA-wvpp-8hx9-p66j (high) | GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token ... |
| GHSA-jm78-9fvv-mhgr (high) | GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling ... |
| GHSA-hmq2-w58f-27jc (high) | GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules... |
| GHSA-3f7w-8rr8-f37f (high) | GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enab... |
| GHSA-4gmw-gg2m-w46p (high) | GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enab... |
| GHSA-539m-9xh6-q6rr (medium) | GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, ... |
| GHSA-6p8h-3wgx-97gf (high) | GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary comma... |
| GHSA-94p4-4cq8-9g67 (high) | GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incompl... |
| GHSA-9rj7-rf2p-w77r (high) | GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via -... |
| GHSA-fjr4-x663-mwxc (high) | GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (ke... |
| GHSA-hh9p-6wh2-4mfc (medium) | GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() |
| GHSA-hmq2-w58f-27jc (high) | GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules... |
| GHSA-jm78-9fvv-mhgr (high) | GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling ... |
| GHSA-p538-c434-8v24 (medium) | GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Co... |
| GHSA-r9mr-m37c-5fr3 (high) | GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enable... |
| GHSA-wvpp-8hx9-p66j (high) | GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token ... |
Data from Homebrew/advisory-database. Run brew vulns mentat for a live check.
Analytics:
| 30 days | 90 days | 365 days | |
|---|---|---|---|
| Installs | 2 | 4 | 64 |
| Installs on Request | 2 | 4 | 64 |
| Build Errors | 0 |