This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryAsync tasks are now scoped to their MCP connection and CORS is disabled by default.
Full changelog
Docker image
docker pull ghcr.io/freema/openclaw-mcp:1.7.0
See deployment docs for full setup instructions.
What's Changed
- chore(ci): switch PR reviews from CI Action to CodeForge server by @freema in https://github.com/freema/openclaw-mcp/pull/39
- fix(security): scope async tasks to their MCP connection, disable CORS by default by @freema in https://github.com/freema/openclaw-mcp/pull/40
Full Changelog: https://github.com/freema/openclaw-mcp/compare/1.6.0...1.7.0
Security Fixes
- fix(security): scope async tasks to their MCP connection, disable CORS by default
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About freema/openclaw-mcp
MCP server for OpenClaw AI assistant integration. Enables Claude to delegate tasks to OpenClaw agents with sync/async tools, OAuth 2.1 auth, and SSE transport for Claude.ai.
Related context
Beta — feedback welcome: [email protected]