Skip to content

blockrunai/blockrun-mcp

v0.25.2 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 28d MCP Search & Web
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai claude-code llm mcp mcp-server x402

Affected surfaces

deps

Summary

AI summary

Pinned viem's ws to 8.21.0 and upgraded @blockrun/llm to 3.5.1 clearing high‑severity npm audit advisories.

Full changelog

Dependency security: a pinned viem transitive [email protected] (below the ≥8.21.0 patch) was flagging the whole ws → viem → @x402/evm → @blockrun/clawrouter → @blockrun/llm chain (5 high). An overrides entry forces viem's ws to 8.21.0 — clearing all of them (npm audit 15 → 11). The override ships in package.json, so every npx install gets the patched ws.

Remaining advisories are out of this repo's control: the Solana web3.js-v1 tree (no upstream fix for bigint-buffer; npm's only "fix" is a breaking downgrade), the intentional [email protected] pin (bumping re-introduces the Node <20.19 ESM break), and a dev-only esbuild.

Also fixed at the source in @blockrun/[email protected] (pnpm overrides for ws+form-data, dev-tool bump — 0 critical, runtime highs cleared). No source changes; 84 tests + build + live wallet smoke green.

Security Fixes

  • Upgraded `viem`'s transitive dependency `ws` from 8.20.1 to 8.21.0 via package.json overrides, clearing high‑severity npm audit advisories (15 → 11).
  • Updated `@blockrun/llm` to 3.5.1 which applies pnpm overrides for `ws` and `form-data`, resolving remaining runtime security issues.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track blockrunai/blockrun-mcp

Get notified when new releases ship.

Sign up free

About blockrunai/blockrun-mcp

Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.

All releases →

Beta — feedback welcome: [email protected]