This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 18d
Developer Productivity
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
android
android-emulator
app-testing
appetize-alternative
browserstack-alternative
developer-tools
+13 more
emulator
flutter
ios
ios-simulator
macos
mcp
mobile-qa
mobile-testing
qa-tools
react-native
self-hosted
simulator
testing
Affected surfaces
rce_ssrf
breaking_upgrade
Summary
AI summaryFixes path traversal vulnerability in /uploads/ and removes unauthenticated WebSocket access.
Full changelog
What's Changed
- fix: bump mcp-server to 0.4.0-experimental.1 and guard release CI by @jo-duchan in https://github.com/jo-duchan/tapflow/pull/172
- fix: path traversal in /uploads/ and unauthenticated WebSocket access by @jo-duchan in https://github.com/jo-duchan/tapflow/pull/173
- chore: release v0.4.1 — security patch by @jo-duchan in https://github.com/jo-duchan/tapflow/pull/174
Full Changelog: https://github.com/jo-duchan/tapflow/compare/v0.4.0...v0.4.1
Security Fixes
- Fix: path traversal in /uploads/
- Fix: unauthenticated WebSocket access
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Tapflow
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]