This release includes 1 security fix for security teams reviewing exposed deployments.
Published 28d
MCP Developer Tools
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai-agents
api-gateway
chatgpt
chatgpt-apps
claude
claude-connectors
+14 more
database-mcp-server
gemini
graphql-to-mcp
mcp
mcp-gateway
mcp-servers
model-context-protocol
no-code
openapi-to-mcp
rest-to-mcp
self-hosted
soap-to-mcp
sql-to-mcp
typescript
Affected surfaces
rce_ssrf
auth
Summary
AI summaryIntroduces Knowledge Graph, AI skills, usage analytics, and security hardening features.
Full changelog
v0.2.0 — Knowledge Graph, AI skills, usage analytics & security hardening
A "smart, AI-empowered gateway" release. All AI features are opt-in and inert by default.
- Knowledge Graph: per-workspace PII-safe data-relationship graph served over MCP (
kg_how_to_obtain), visual editor + redesigned canvas, optional LLM enrichment (cost-capped, batched). - AI skills: rules captured from real tool-call intents, composed into MCP server instructions (not extra tools); search/tabs/pagination, auto-apply, AI consolidate.
- Usage & cost analytics:
/analytics+/api/audit/breakdownsper connector/server/user with proxy metering and a volume-based cost estimate. - Security hardening: SSRF guard on the DatabaseEngine; RLS foundation (off by default) with a real-DB isolation proof; prototype-pollution guard on outputSchema inference.
- Migrations: 10 additive, auto-applied on container start.
Security Fixes
- SSRF guard added to DatabaseEngine; RLS foundation (off by default) with DB isolation proof; prototype‑pollution guard on outputSchema inference.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About AnythingMCP
All releases →Related context
Beta — feedback welcome: [email protected]