This release includes 1 security fix for security teams reviewing exposed deployments.
Published 18d
MCP Developer Tools
✓ No known CVEs patched
This release patches 1 known CVE
Topics
infrastructure
kubernetes
mcp
server
Affected surfaces
rce_ssrf
Summary
AI summaryGuarded port_forward tool arguments against kubectl flag injection.
Full changelog
Security fix: guard the port_forward tool's argv against kubectl flag injection, closing the last unguarded exec path from the argument-injection report (#328).
Security Fixes
- Guarded the port_forward tool's argv against kubectl flag injection, closing the last unguarded exec path from the argument‑injection report (#328).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]