This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
MCP Data & Storage
✓ No known CVEs patched
This release patches 1 known CVE
Topics
agent-memory-system
anthropic
artificial-intelligence
causal-inference
claude
claude-code
+14 more
claude-code-plugin
cognitive-architecture
cognitive-science
episodic-memory
hopfield-network
llm-memory
long-term-memory
mcp-server
model-context-protocol
neuroscience
persistent-memory
predictive-coding
retrieval-augmented-generation
vector-db
Affected surfaces
rce_ssrf
Summary
AI summaryHardened path sanitization to prevent CodeQL injection vulnerabilities.
Full changelog
- fix: bump pyproject.toml version to 3.4.2 for PyPI release
- fix: remove unused os import in http_server.py
- fix: remove duplicate shell=False kwarg in git_diff.py
- style: format launcher.py and setup.py
- feat: cross-platform setup.py for Windows support
- fix: harden path sanitization for CodeQL — pre-validate before resolve()
Full Changelog: https://github.com/cdeust/Cortex/compare/v3.4.1...v3.4.2
Security Fixes
- Harden path sanitization for CodeQL by pre-validating paths before resolution
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About cdeust/Cortex
Persistent memory for Claude Code grounded in computational neuroscience (41 cited papers)
Related context
Beta — feedback welcome: [email protected]