This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 28d
MCP Developer Tools
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
ai-agents
api-gateway
chatgpt
chatgpt-apps
claude
claude-connectors
+14 more
database-mcp-server
gemini
graphql-to-mcp
mcp
mcp-gateway
mcp-servers
model-context-protocol
no-code
openapi-to-mcp
rest-to-mcp
self-hosted
soap-to-mcp
sql-to-mcp
typescript
Affected surfaces
rce_ssrf
auth
Summary
AI summaryObservational ingest stability fixes reduce memory/CPU usage from peak ~3 GB to ~1 GB.
Full changelog
v0.2.2
Knowledge Graph + AI skills + usage analytics + security hardening, with the
observational-ingest stability fixes.
Features (since 0.1.x):
- Knowledge Graph (static + observational), served over MCP via
kg_how_to_obtain; visual editor; optional LLM enrichment (OpenAI/OpenRouter/Anthropic). - AI skills from captured intents, composed into MCP server instructions; search/tabs/pagination, auto-apply, AI consolidate.
- Usage & cost analytics (
/analytics,/api/audit/breakdowns). - Security: SSRF guard on the DatabaseEngine; RLS foundation (off by default); prototype-pollution guard on outputSchema inference.
Stability fixes (0.2.1 → 0.2.2):
- kg-discovery observational ingest streamed in pages with per-page flush + a JSON-walk node cap → bounded memory/CPU (peak ~1 GB, was ~3 GB → OOM).
start.shexits (→ container restart) if either process dies; backend V8 heap cap.
All migrations are additive and auto-applied on container start.
Security Fixes
- SSRF guard added to DatabaseEngine
- Prototype‑pollution guard implemented for outputSchema inference
- RLS foundation introduced (default disabled)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About AnythingMCP
All releases →Related context
Beta — feedback welcome: [email protected]