This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryOAuth key provisioning fixed against Cloudflare origin and OpenAI profile hardened.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
OpenAI-profile hardened against potential abuse. OpenAI-profile hardened against potential abuse. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Cursor marketplace manifest added (issue #54). Cursor marketplace manifest added (issue #54). Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
ChatGPT submission kit refreshed (issue #52). ChatGPT submission kit refreshed (issue #52). Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
OAuth key provisioning fixed against CF origin. OAuth key provisioning fixed against CF origin. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
verifactu_status returns honest 404 semantics. verifactu_status returns honest 404 semantics. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Refactor | Low |
MCP mutations now unwrap {data,meta} envelope for all resources. MCP mutations now unwrap {data,meta} envelope for all resources. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Refactor | Low |
Public surface scrubbed per issues #53 and #60. Public surface scrubbed per issues #53 and #60. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Invoices (and every resource) operable again through MCP mutations: {data,meta} envelope unwrapped on all mutations and single-object reads (#64, #65). Over-strict output schemas relaxed with anti-envelope tripwire test. verifactu_status honest 404 semantics. OAuth key provisioning fixed against CF origin (#56). Cursor marketplace manifest (#54) + ChatGPT submission kit refresh (#52). OpenAI-profile hardening (#57–#59), public surface scrub (#53, #60).
Full changelog: https://github.com/Frihet-io/frihet-mcp/blob/main/CHANGELOG.md
Security Fixes
- OpenAI-profile hardening (#57–#59)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About @frihet/mcp-server
AI-native business management — invoices, expenses, clients, products, and quotes. 31 tools for Claude, Cursor, Windsurf, and Cline.
Related context
Beta — feedback welcome: [email protected]