Skip to content

Flagsmith

v2.239.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ci-cd docker feature-flag feature-flaggers feature-flagging feature-flags
+9 more
feature-management feature-toggles flagsmith multivariate-testing python react remote-config remote-control self-hosted

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

The release bumps PyJWT to version 2.13.0, which patches CVE‑2026‑48526.

Why it matters: CVE‑2026‑48526 has a severity score of 90; upgrading PyJWT to 2.13.0 eliminates the vulnerability for any application using this library.

Summary

AI summary

Updates 2.239.0, Dependency Updates, and CI across a mixed release.

Changes in this release

Security Critical

Bump PyJWT to 2.13.0, fixing CVE-2026-48526.

Bump PyJWT to 2.13.0, fixing CVE-2026-48526.

Source: llm_adapter@2026-06-08

Confidence: high

Security High

Update pytest to version 9, addressing security issues.

Update pytest to version 9, addressing security issues.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Breaking High

Make evaluation result variant required and nullable in SDK.

Make evaluation result variant required and nullable in SDK.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Medium

Add metric search, experiments field and update.

Add metric search, experiments field and update.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Medium

Allow choosing project administrators during project creation.

Allow choosing project administrators during project creation.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Medium

Introduce environment‑scoped metrics and experiment results.

Introduce environment‑scoped metrics and experiment results.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Medium

Add Docker image and release publishing for MCP.

Add Docker image and release publishing for MCP.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Medium

Emit session and tool call events in MCP.

Emit session and tool call events in MCP.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Medium

Expose Prometheus metrics for MCP.

Expose Prometheus metrics for MCP.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Medium

Add OAuth 2.0 support for HTTP transport in MCP.

Add OAuth 2.0 support for HTTP transport in MCP.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Medium

Run an MCP server from OpenAPI specifications.

Run an MCP server from OpenAPI specifications.

Source: llm_adapter@2026-06-08

Confidence: high

Feature Low

Add per-feature unique key to multivariate options.

Add per-feature unique key to multivariate options.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Feature Low

Report variant key on identities flag responses for multivariate.

Report variant key on identities flag responses for multivariate.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Feature Low

Thread variant key into the environment document for multivariate.

Thread variant key into the environment document for multivariate.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Feature Low

Add variant key to evaluation schemas in SDK.

Add variant key to evaluation schemas in SDK.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Dependency Low

Bump uv to 0.11.18.

Bump uv to 0.11.18.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Dependency Low

Update python-dotenv and idna (transitive dependencies).

Update python-dotenv and idna (transitive dependencies).

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Dependency Low

Update sentry webpack plugin.

Update sentry webpack plugin.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Bugfix Medium

Fix uv compatibility in local environments.

Fix uv compatibility in local environments.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

Full changelog

2.239.0 (2026-06-08)

Features

  • add metric search, experiments field and update (#7724) (3d34cbc)
  • choose project administrators on project creation (#7580) (1bf8bda)
  • experimentation: environment-scoped metrics & experiment results (#7674) (f4b246e)
  • MCP: Add Docker image and release publishing (#7694) (19fa405)
  • MCP: Emit session and tool call events (#7707) (36ef8dd)
  • MCP: Expose Prometheus metrics (#7705) (8ef95e0)
  • MCP: OAuth 2.0 support for HTTP transport (#7692) (35664ed)
  • MCP: Run an MCP server out of OpenAPI specs (#7670) (4688419)
  • MCP: Set up logging and OpenTelemetry export (#7706) (f3c738b)
  • multivariate: add per-feature unique key to multivariate options (#7698) (6fcede7)
  • multivariate: report variant key on identities flag responses (#7723) (08b9690)
  • multivariate: thread variant key into the environment document (#7699) (ed18061)
  • sdk: add variant key to evaluation schemas (#7704) (2eae0ff)
  • sdk: make evaluation result variant required and nullable (#7726) (9036dbf)
  • verify warehouse connection api and events received (#7677) (d0ac9b5)

Bug Fixes

  • API: bump PyJWT to 2.13.0 (CVE-2026-48526) and add to dev dependencies (#7714) (09bac40)
  • Improve ButterBar text contrast on banners (#7684) (cf0d7b0)
  • infra: Drop SECURE_PROXY_SSL_HEADER_NAME override (#7499) (ab37e29)
  • Runtime: Fix uv compatibility in local envs (#7720) (4ffbf74)

Dependency Updates

CI

Security Fixes

  • CVE-2026-48526 — bump PyJWT to 2.13.0 (API dependency)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Flagsmith

Get notified when new releases ship.

Sign up free

About Flagsmith

Dashboard, API and SDKs for adding Feature Flags to your applications (alternative to LaunchDarkly).

All releases →

Related context

Related CVEs

Beta — feedback welcome: [email protected]