Skip to content

Flagsmith

v2.242.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ci-cd docker feature-flag feature-flaggers feature-flagging feature-flags
+9 more
feature-management feature-toggles flagsmith multivariate-testing python react remote-config remote-control self-hosted

Affected surfaces

deps

Summary

AI summary

Updates Dependency Updates, 2.242.0, and Bug Fixes across a mixed release.

Full changelog

2.242.0 (2026-06-16)

Features

  • experiments: attach a primary metric in the create experiment wizard (#7780) (76fb3e3)
  • MCP: Serve MCP at the bare server URL (#7797) (90b08f1)

Bug Fixes

  • frontend: add guard against null model (#7778) (5665ad0)
  • MCP: Bare server URL fails OAuth resource validation (#7798) (537b57e)
  • trigger get warehouse stat request (#7794) (cdc3c06)

Dependency Updates

  • frontend: update dependency dompurify to v3.4.9 [security] (#7790) (e927630)

Docs

  • MCP: Document self-hosting the MCP server (#7800) (cfdf9dc)
  • MCP: Rewrite MCP server page and generate the tool catalogue (#7668) (9c8cff0)

Security Fixes

  • dep: dompurify updated to v3.4.9 (security)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Flagsmith

Get notified when new releases ship.

Sign up free

About Flagsmith

Dashboard, API and SDKs for adding Feature Flags to your applications (alternative to LaunchDarkly).

All releases →

Related context

Earlier breaking changes

  • v2.239.0 Make evaluation result variant required and nullable in SDK.

Beta — feedback welcome: [email protected]