Skip to content

cameronrye/openzim-mcp

v2.4.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo MCP Data & Storage
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

kiwix mcp mcp-server openzim zim

Affected surfaces

deps

Summary

AI summary

Fixed 16 real‑world issues discovered during zim_query testing and cleared npm‑audit advisories for esbuild and yaml dependencies.

Changes in this release

Dependency Medium

Clear website npm-audit advisories for esbuild and yaml dependencies.

Clear website npm-audit advisories for esbuild and yaml dependencies.

Source: llm_adapter@2026-06-15

Confidence: high

Bugfix Medium

Resolve 16 findings from real-world zim_query testing.

Resolve 16 findings from real-world zim_query testing.

Source: llm_adapter@2026-06-15

Confidence: high

Full changelog

2.4.2 (2026-06-15)

Fixed

  • deps: clear website npm-audit advisories (esbuild, yaml) (#288) (41dffd6)
  • resolve 16 findings from real-world zim_query testing (#287) (bbb9382)

Security Fixes

  • deps: cleared npm‑audit advisories for esbuild and yaml

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track cameronrye/openzim-mcp

Get notified when new releases ship.

Sign up free

About cameronrye/openzim-mcp

Modern, secure MCP server for accessing ZIM format knowledge bases offline. Enables AI models to search and navigate Wikipedia, educational content, and other compressed knowledge archives with smart retrieval, caching, and comprehensive API.

All releases →

Related context

Earlier breaking changes

  • v2.0.0a15 _attribute_sections falls back to first section when no section brackets located passage
  • v2.0.0a13 canonical‑splice gate tightened to require exact path equality, fixing H2/H3 surface end‑to‑end behavior across all shapes.
  • v2.0.0a11 Exposed `content_offset` as top-level `zim_query` parameter, validated >=0, threaded through options.
  • v2.0.0a10 `get article M/<key>` now returns ZIM metadata entry rather than aliased C-namespace article body.
  • v2.0.0a10 `metadata for <file>` returns concise metadata strings instead of full article bodies for new-scheme archives.

Beta — feedback welcome: [email protected]