This release includes 1 security fix for security teams reviewing exposed deployments.
Published 18d
MCP Developer Tools
✓ No known CVEs patched
This release patches 1 known CVE
Topics
infrastructure
kubernetes
mcp
server
Affected surfaces
auth
breaking_upgrade
Summary
AI summaryMask Kubernetes Secret values regardless of resourceType, fixing a masking bypass in kubectl_get.
Full changelog
Security fix: mask Kubernetes Secret values regardless of the resourceType syntax used to request them (e.g. secret/<name>), closing a masking bypass in kubectl_get (GHSA-w23h-64x4-22h9).
Security Fixes
- GHSA-w23h-64x4-22h9 — mask Kubernetes Secret values regardless of resourceType syntax, closing a masking bypass in kubectl_get
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]