This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
ReleasePort's take
Light signalThe release updates dependency mcp from version 1.26.0 to 1.28.1.
Why it matters: Patches CVE-2026-52869, CVE-2026-52870, and CVE-2026-59950; upgrade required for affected deployments.
Summary
AI summaryBump mcp from 1.26.0 to 1.28.1 to clear CVE-2026-52869, CVE-2026-52870 and CVE-2026-59950.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Bumps dependency mcp from 1.26.0 to 1.28.1 to patch CVE-2026-52869, CVE-2026-52870, and CVE-2026-59950. Bumps dependency mcp from 1.26.0 to 1.28.1 to patch CVE-2026-52869, CVE-2026-52870, and CVE-2026-59950. Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
Changes
- chore(release): v1.25.5 — the phone assistant becomes trustworthy, and the planner learns to converge (374cd2c0)
- chore(release): v1.25.4 — the Grafana fleet becomes complete, readable and honest (25 dashboards, 419/419 metrics covered) (12d030f0)
- fix(security): bump mcp 1.26.0 -> 1.28.1 to clear CVE-2026-52869/52870/59950 (06a482d8)
Docker Images
docker pull ghcr.io/jgouviergmail/LIA-Assistant/api:v1.25.5
docker pull ghcr.io/jgouviergmail/LIA-Assistant/web:v1.25.5
Quick Start
git clone https://github.com/jgouviergmail/LIA-Assistant.git
cd LIA-Assistant
cp .env.example .env
docker compose up -d
Full Changelog: https://github.com/jgouviergmail/LIA-Assistant/compare/v1.25.3...v1.25.5
Security Fixes
- CVE-2026-52869, CVE-2026-52870, CVE-2026-59950 — fixed by bumping mcp from 1.26.0 to 1.28.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About LIA
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]