Skip to content

@frihet/mcp-server

v1.15.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 16d MCP SaaS Integrations
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

accounting ai ai-agent ai-native automation billing
+14 more
business-management claude claude-code-plugin claude-code-skill cloudflare-workers erp fintech invoicing llm mcp mcp-server saas tax-compliance typescript

Affected surfaces

auth breaking_upgrade

Summary

AI summary

OAuth key provisioning fixed against Cloudflare origin and OpenAI profile hardened.

Changes in this release

Security High

OpenAI-profile hardened against potential abuse.

OpenAI-profile hardened against potential abuse.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Cursor marketplace manifest added (issue #54).

Cursor marketplace manifest added (issue #54).

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

ChatGPT submission kit refreshed (issue #52).

ChatGPT submission kit refreshed (issue #52).

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

OAuth key provisioning fixed against CF origin.

OAuth key provisioning fixed against CF origin.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Low

verifactu_status returns honest 404 semantics.

verifactu_status returns honest 404 semantics.

Source: llm_adapter@2026-07-15

Confidence: high

Refactor Low

MCP mutations now unwrap {data,meta} envelope for all resources.

MCP mutations now unwrap {data,meta} envelope for all resources.

Source: llm_adapter@2026-07-15

Confidence: high

Refactor Low

Public surface scrubbed per issues #53 and #60.

Public surface scrubbed per issues #53 and #60.

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog

Invoices (and every resource) operable again through MCP mutations: {data,meta} envelope unwrapped on all mutations and single-object reads (#64, #65). Over-strict output schemas relaxed with anti-envelope tripwire test. verifactu_status honest 404 semantics. OAuth key provisioning fixed against CF origin (#56). Cursor marketplace manifest (#54) + ChatGPT submission kit refresh (#52). OpenAI-profile hardening (#57–#59), public surface scrub (#53, #60).

Full changelog: https://github.com/Frihet-io/frihet-mcp/blob/main/CHANGELOG.md

Security Fixes

  • OpenAI-profile hardening (#57–#59)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track @frihet/mcp-server

Get notified when new releases ship.

Sign up free

About @frihet/mcp-server

AI-native business management — invoices, expenses, clients, products, and quotes. 31 tools for Claude, Cursor, Windsurf, and Cline.

All releases →

Beta — feedback welcome: [email protected]