This release includes 1 security fix for security teams reviewing exposed deployments.
Affected surfaces
Summary
AI summaryBumped axios floor from ^1.13.6 to ^1.15.2 resolving 13 Dependabot alerts.
Full changelog
Security patch release
Resolves 13 open Dependabot alerts (1 high, 12 moderate) via transitive dependency updates and an axios version floor bump.
Fixed
- Bumped
axiosfloor from^1.13.6to^1.15.2 npm audit fixresolved transitives:hono,@hono/node-server,path-to-regexp,follow-redirectsnpm auditnow reports 0 vulnerabilities
Notes on real-world risk
All 13 alerts were effectively unreachable in this project:
- This is a stdio-only MCP server — the vulnerable
hono/@hono/node-server/path-to-regexppaths live in the MCP SDK's optional HTTP transport, which is never instantiated here. - The
axiosSSRF alerts require proxy env vars plus attacker-controlled URLs; this client only calls the hard-codedhttps://validator.iaptic.com/v3endpoint.
Patching anyway for hygiene and to keep downstream consumers' audit logs clean.
Full Changelog: https://github.com/iaptic/mcp-server-iaptic/compare/v1.2.0...v1.2.1
Security Fixes
- Bumped axios minimum version to ^1.15.2 resolving high (1) and moderate (12) Dependabot alerts
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About iaptic/mcp-server-iaptic
Connect with iaptic to ask about your Customer Purchases, Transaction data and App Revenue statistics.
Related context
Beta — feedback welcome: [email protected]