This release includes 1 security fix for security teams reviewing exposed deployments.
Published 4d
MCP Developer Tools
✓ No known CVEs patched
This release patches 1 known CVE
Affected surfaces
auth
rce_ssrf
Summary
AI summaryUpdates v0.20.1, 81c6b6c, and e761784 across a mixed release.
Full changelog
What's Changed
- Security hardening: WebSocket Origin validation, SSRF, XSS, plan confirmation bypass, path traversal (v0.20.1) (#252) (3078676)
- Update python Docker tag to v3.14 (#221) (81c6b6c)
- Stop Renovate duplicating Dependabot's github-actions and security PRs (#250) (e761784)
- Fix test_windows_event_loop_policy for Python 3.14 (#251) (21fcc8e)
- Update softprops/action-gh-release action to v3 (#249) (ed8d3dc)
- Update GitHub Artifact Actions (#223) (8a9d5d4)
- Update actions/checkout action to v7 (#246) (a525f1f)
- Explicitly dispatch publish.yml from release.yml (4733837)
Full Changelog: https://github.com/IBM/mcp-cli/compare/v0.20.0...v0.20.1
Security Fixes
- WebSocket Origin validation, SSRF protection, XSS mitigation, plan confirmation bypass fix, path traversal defense
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]