This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryPath security hardening rejects symlink-based containment escapes and validation tightening adds input‑length checks.
Full changelog
What's Changed
- NVM config self-heal (#2338, #2339) — MCP client configs (Claude Desktop, Cursor, Windsurf, LM Studio, Gemini CLI, VS Code, Cline) left pointing at a dead NVM launcher wrapper are repaired automatically on server startup: bare
npxis restored when NVM is absent, or the real launcher is regenerated when NVM is present (preserving the #1902 protection). A guardrail prevents temp-directory wrapper paths from ever being written into a client config, and the test suite is fully isolated from real client configs. - Path security hardening (#2334) — reject symlink-based containment escapes from allowed directories; preserve element metadata and base-path handling through edit operations. (Remaining missing-base ancestor case tracked in #2342.)
- Validation tightening (#2334) — content validator input-length checks; explicit ensemble element updates.
Full Changelog: https://github.com/DollhouseMCP/mcp-server/compare/v2.0.36...v2.0.37
Security Fixes
- Path security hardening prevents symlink‑based containment escape attacks.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About DollhouseMCP/mcp-server
One-line installable MCP server that adds reusable customization elements — personas, skills, templates, agents, memory, and ensembles (collected customization tools)
Related context
Beta — feedback welcome: [email protected]