This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+9 more
Affected surfaces
ReleasePort's take
Moderate signalVersion v0.6.6 hardens localhost authentication to prevent bypass and locks down admin CORS.
Why it matters: Security severity rated 90; protects admin authentication surface from bypass attacks.
Summary
AI summaryHardened localhost authentication bypass and locked down admin CORS.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Hardens localhost authentication to prevent bypass. Hardens localhost authentication to prevent bypass. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Security | Medium |
Restricts admin CORS origins to mitigate cross-origin attacks. Restricts admin CORS origins to mitigate cross-origin attacks. Source: granite4.1:30b@2026-06-15-audit Confidence: low |
— |
Full changelog
Changelog
- 470e4cda7d7f88f37213ad40812cf50e3adddec6 fix(admin): harden localhost auth bypass and lock down admin CORS (#33)
Security Fixes
- Hardened localhost authentication bypass and locked down admin CORS.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About getmockd/mockd
Multi-protocol API mock server with 18 MCP tools. Mock HTTP, GraphQL, gRPC, WebSocket, MQTT, SSE, and SOAP APIs with chaos engineering, stateful CRUD, 8 import formats (OpenAPI, Postman, HAR, WireMock, cURL, Mockoon, WSDL), and deterministic seeded responses.
Related context
Beta — feedback welcome: [email protected]