This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
Summary
AI summaryFixed high-severity cross‑client data leak in @modelcontextprotocol/sdk and moderate XSS/cache deception in hono.
Full changelog
Security fix: updated @modelcontextprotocol/sdk (high: cross-client data leak) and hono (moderate: XSS + cache deception). All 52 tests pass.
Security Fixes
- CVE‑XXXX‑XXXXX – high severity cross‑client data leak in @modelcontextprotocol/sdk
- CVE‑XXXX‑XXXXX – moderate severity XSS and cache deception in hono
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About dorukardahan/twitterapi-docs-mcp
Offline access to TwitterAPI.io documentation for AI assistants. 52 API endpoints, guides, pricing info, and authentication docs.
Related context
Beta — feedback welcome: [email protected]