Skip to content

Brand-System/brandsystem-mcp

v0.14.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 8d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents brand-governance brand-guidelines brand-identity brand-voice claude
+5 more
codex cursor design-tokens mcp model-context-protocol

Affected surfaces

rce_ssrf

Summary

AI summary

Fixed-point SVG comment removal now correctly propagates to npm packages.

Changes in this release

Feature Low

Enforces benchmark validators to match instructions literally, including sentence counts and structure requirements.

Enforces benchmark validators to match instructions literally, including sentence counts and structure requirements.

Source: granite4.1:30b@2026-07-18-audit

Confidence: low

Bugfix Medium

Corrects preflight message to accurately reflect unresolved CSS variable WARN status.

Corrects preflight message to accurately reflect unresolved CSS variable WARN status.

Source: llm_adapter@2026-07-18

Confidence: low

Bugfix Medium

Fixes interleaved SVG comment fragments that could reassemble into a live `<!--` after sanitization.

Fixes interleaved SVG comment fragments that could reassemble into a live `<!--` after sanitization.

Source: llm_adapter@2026-07-18

Confidence: low

Bugfix Low

Updates preflight warning message to correctly indicate unresolved CSS variables instead of claiming all checks pass.

Updates preflight warning message to correctly indicate unresolved CSS variables instead of claiming all checks pass.

Source: granite4.1:30b@2026-07-18-audit

Confidence: low

Full changelog

Release-boundary closure: v0.14.2 was tagged before the final CodeQL fix merged, so npm consumers lacked it. This release ships everything to installed packages.

  • Fixed-point SVG comment removal reaches npm — interleaved comment fragments cannot reassemble into a live <!-- after sanitization (closes the last CodeQL alert for consumers, not just the repo)
  • Preflight message matches its verdict — a WARN from unresolved CSS variables no longer claims "All checks pass"; it says what to define before the content can be verified
  • Benchmark validators enforce instructions literally — blog exactly-3-sentences, CTA headline + button + style block (must_match arrays, min_sentences)

With this release: zero open CodeQL alerts, zero Dependabot alerts, zero npm advisories — true for the artifact users install, not merely for main.

Full changelog: https://github.com/Brandcode-Studio/brandsystem-mcp/blob/main/CHANGELOG.md

Security Fixes

  • Prevents reassembly of interleaved SVG comment fragments that could lead to malicious payload injection.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Brand-System/brandsystem-mcp

Get notified when new releases ship.

Sign up free

About Brand-System/brandsystem-mcp

Make your brand machine-readable. Extract brand identity (colors, fonts, logo, voice, visual rules) from any website via static CSS + rendered-page extraction, compile into DTCG tokens, brand runtime contracts, and interaction policies. 34 tools across 4 progressive sessions. Subscribable `brand://runtime` and `brand://policy` MCP resources. Content compliance scoring (0-100), pass/fail gate, and HTML/CSS preflight. Brandcode Studio connector for hosted brand sync.

All releases →

Beta — feedback welcome: [email protected]