Skip to content

DollhouseMCP/mcp-server

v2.0.38 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 22d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agents ai ai-tools claude codex cursor
+14 more
dollhousemcp ensembles llm mcp mcp-server memory model-context-protocol personas prompt-engineering skills templates typescript vscode windsurf

Affected surfaces

rce_ssrf

Summary

AI summary

Symlink containment fixes close remaining path‑security bypasses for convert CLI output paths.

Full changelog

What's Changed

  • Symlink containment completed (#2342, #2343, #2344, #2346) — closes both path-security bypasses for convert CLI output paths, including the remaining case disclosed in the v2.0.37 release notes:
    • Output directories that do not exist yet are vetted through their nearest existing ancestor (#2343).
    • Canonical containment (#2346): relative outputs — including the default — must truly resolve inside the working directory, even when a symlink (or a symlink whose target already contains matching subdirectories) tries to redirect them. Explicit outside destinations disclose their real location when a symlink diverts them, and writes always use the vetted canonical path.

No known path-security issues remain open.

Full Changelog: https://github.com/DollhouseMCP/mcp-server/compare/v2.0.37...v2.0.38

Security Fixes

  • Symlink containment completed — closes both path‑security bypasses for convert CLI output paths (CVE not disclosed).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track DollhouseMCP/mcp-server

Get notified when new releases ship.

Sign up free

About DollhouseMCP/mcp-server

One-line installable MCP server that adds reusable customization elements — personas, skills, templates, agents, memory, and ensembles (collected customization tools)

All releases →

Beta — feedback welcome: [email protected]