This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summarySymlink containment fixes close remaining path‑security bypasses for convert CLI output paths.
Full changelog
What's Changed
- Symlink containment completed (#2342, #2343, #2344, #2346) — closes both path-security bypasses for convert CLI output paths, including the remaining case disclosed in the v2.0.37 release notes:
- Output directories that do not exist yet are vetted through their nearest existing ancestor (#2343).
- Canonical containment (#2346): relative outputs — including the default — must truly resolve inside the working directory, even when a symlink (or a symlink whose target already contains matching subdirectories) tries to redirect them. Explicit outside destinations disclose their real location when a symlink diverts them, and writes always use the vetted canonical path.
No known path-security issues remain open.
Full Changelog: https://github.com/DollhouseMCP/mcp-server/compare/v2.0.37...v2.0.38
Security Fixes
- Symlink containment completed — closes both path‑security bypasses for convert CLI output paths (CVE not disclosed).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About DollhouseMCP/mcp-server
One-line installable MCP server that adds reusable customization elements — personas, skills, templates, agents, memory, and ensembles (collected customization tools)
Related context
Beta — feedback welcome: [email protected]