Skip to content

Aiven-Open/mcp-aiven

v1.0.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 28d MCP Data & Storage
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Affected surfaces

auth

Summary

AI summary

Added remote read‑only support via query parameter.

Full changelog

What's Changed

  • feat: mcp metrics headers by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/16
  • feat: aiven apps [EVERSQL-1756] by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/22
  • Yonatan dvir mcp bugs and improvements by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/18
  • Add application metrics tool by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/17
  • mcp: refuse PostgreSQL connection when CA certificate is unavailable [EVERSQL-1759] by @tomershay in https://github.com/Aiven-Open/mcp-aiven/pull/21
  • filter service_type_plans fields to reduce context size by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/23
  • mcp improvements by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/24
  • feat: aiven apps vpc by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/25
  • use mcp.aiven.live host by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/26
  • mcp: support deploying from apps private git repos by @keren-tevet in https://github.com/Aiven-Open/mcp-aiven/pull/27
  • fix: return 405 on SSE get request by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/29
  • mcp: Add service to service integrations [EVERSQL-1760] by @keren-tevet in https://github.com/Aiven-Open/mcp-aiven/pull/30
  • show a warning before adding public endpoint by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/31
  • fix: increase rate limit by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/32
  • feat: npx pre-publish alignment by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/33
  • MCP version 0.1.5 by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/13
  • fix: fix base directory default path and fetch all repos when listing vcs by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/36
  • fix: change the tokens creation link by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/37
  • fix: fix the 401 error hint by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/39
  • mcp: add rate limit to /mcp endpoint [EVERSQL-1789] by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/38
  • mcp: wrap tool responses in an untrusted-data boundary to prevent prompt injection by @tomershay in https://github.com/Aiven-Open/mcp-aiven/pull/41
  • mcp: add response fields to description in tool manifests by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/43
  • feat: add remote read_only support by query param by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/44
  • feat: make MCP host URL configurable via MCP_HOST env var by @keren-tevet in https://github.com/Aiven-Open/mcp-aiven/pull/46
  • feat: add docs search tool by @tomershay in https://github.com/Aiven-Open/mcp-aiven/pull/45
  • fix: clarify kafka connect list tool does not return runtime state by @roman-pozd in https://github.com/Aiven-Open/mcp-aiven/pull/47
  • feat: add observability headers and reasoning field to all tools by @yoni-nezer-aiven in https://github.com/Aiven-Open/mcp-aiven/pull/40
  • add a wrap of untrusted response for optimizer, vcs and redeploy tool results by @yonatan-dvir in https://github.com/Aiven-Open/mcp-aiven/pull/48
  • fix: prevent default truncation when fetching metrics by @tomershay in https://github.com/Aiven-Open/mcp-aiven/pull/52
  • feat: add source label to docs search calls by @tomershay in https://github.com/Aiven-Open/mcp-aiven/pull/51
  • feat: add CI and release github actions workflows, bump version to 1.0.0 by @keren-tevet in https://github.com/Aiven-Open/mcp-aiven/pull/49
  • fix: set git identity before creating annotated tag by @keren-tevet in https://github.com/Aiven-Open/mcp-aiven/pull/56

New Contributors

  • @roman-pozd made their first contribution in https://github.com/Aiven-Open/mcp-aiven/pull/16
  • @tomershay made their first contribution in https://github.com/Aiven-Open/mcp-aiven/pull/21
  • @yoni-nezer-aiven made their first contribution in https://github.com/Aiven-Open/mcp-aiven/pull/40

Full Changelog: https://github.com/Aiven-Open/mcp-aiven/commits/v1.0.0

Security Fixes

  • mcp: wrap tool responses in an untrusted-data boundary to prevent prompt injection
  • add a wrap of untrusted response for optimizer, vcs and redeploy tool results

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Aiven-Open/mcp-aiven

Get notified when new releases ship.

Sign up free

About Aiven-Open/mcp-aiven

☁ - Navigate your Aiven projects and interact with the PostgreSQL®, Apache Kafka®, ClickHouse® and OpenSearch® services

All releases →

Beta — feedback welcome: [email protected]