Skip to content

KyuRish/mcp-dashboards

v2.2.0 Security

This release includes 8 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 8 known CVEs

Topics

ai charting chartjs charts claude web
+10 more
data-visualization export interactive mcp mcp-apps mcp-dashboards mcp-server model-context-protocol real-time themes

Affected surfaces

auth rbac rce_ssrf deps

Summary

AI summary

Updates Bug Fixes, Install / Upgrade ```bash, and npx across a mixed release.

Full changelog

5 visual discovery catalogs, 8 documented security fixes, dependency refresh, and a wave of robustness work.

Discovery Catalogs

Five new tools for exploring what mcp-dashboards can do, without reading docs. Each catalog tile is a clickable, live, interactive demo - click any card, hit Ask, and the AI routes you to the matching tool.

  • render_catalog - master entry point. One tile per customization dimension (charts / themes / hero variants / effects). The "show me everything" tool.
  • render_chart_catalog - all 31 chart types rendered as mini-previews in a grid.
  • render_theme_catalog - 21 themes side-by-side with color swatches, typography, and effect labels.
  • render_hero_catalog - all 11 hero metric variants (big_number, progress_ring, status, comparison, rank, countdown, threshold, breakdown, NPS, orb, gem).
  • render_effects_catalog - 5 effect presets (none / subtle / shimmer / neon / energetic) with every bundled treatment rendered in-tile: shimmer, glow, glass, hover-lift, scanlines, status pulse, count-up, particles. Uses inline SVG for halo + glass so they survive PNG export through html2canvas-pro.

Just ask "show me the catalog" and you're in.

Security & Hardening

Eight documented improvements, all under-the-hood:

  • SSRF protection for render_from_url and poll_http - DNS-resolves the hostname and blocks all non-unicast ranges (RFC1918, loopback, link-local, AWS metadata 169.254.169.254, IPv6-mapped IPv4 like ::ffff:127.0.0.1). Allowlist override via MCP_URL_ALLOWLIST.
  • Per-host outbound rate limiter - sliding-window slot scheduler (10 req/sec sustained, burst of 20, max 5s wait). Protects external APIs from runaway loops, prevents IP bans. Configurable via MCP_OUTBOUND_RATE_PER_SEC / MCP_OUTBOUND_BURST.
  • HTTP server binds to 127.0.0.1 by default - opt-in to LAN access via MCP_HTTP_BIND_HOST=0.0.0.0.
  • CORS lockdown - only localhost origins permitted by default; configurable via MCP_CORS_ALLOWED_ORIGINS.
  • save_file tool tightened - extension allowlist (.png, .csv only), restricted to app visibility (hidden from the LLM).
  • XSS sanitization across hero, slope, waterfall, variance, bullet, dumbbell chart renderers - user-controlled labels/colors validated via sanitizeColor / escapeHtml helpers.
  • Preview-server hardening - generic 500 error response (no filesystem path leaks), lazy cleanup of stale chart files.
  • Inline <script> JSON escape - chart data containing the literal string </script> can no longer prematurely terminate the inline block.

Configuration

New Configuration section in the README documenting all 9 environment variables, including the new MCP_HTTP_BIND_HOST, MCP_CORS_ALLOWED_ORIGINS, MCP_URL_ALLOWLIST, MCP_OUTBOUND_RATE_PER_SEC, MCP_OUTBOUND_BURST, and the existing MCP_DASHBOARDS_RETAIN_DAYS, MCP_DASHBOARDS_DISABLE_PREVIEW, POLL_PRESET_*.

Bug Fixes

  • Hero variant clicks in dashboards used to report "undefined" as the card title. Now c.title threads correctly into the hero payload - clicking a hero metric reports the actual card title.
  • render_dashboard data shape coercion - bar / line / radar / boxplot now accept both Shape A ({labels, datasets}) and Shape B ([{label, value}]). Previously, Shape B would silently produce an empty grid.
  • big_number sparkline color - now respects the per-card color parameter (was hardcoded to the CSS --accent fallback).

Maintenance

  • Dependencies: @modelcontextprotocol/sdk to ^1.29.0, @modelcontextprotocol/ext-apps to ^1.7.2
  • Two new utility tools: list_chart_files, delete_chart_files for managing the on-disk chart cache (with age filter, cache eviction, robust filename sanitization)
  • MCP tool annotations on all rendering tools (readOnlyHint, idempotentHint, etc.) - improves auto-approval UX in MCP clients
  • A-grade tool descriptions (TDQS scoring) across the catalog
  • Comment cleanups, dead code removal

Install / Upgrade

```bash

Claude Desktop / Code (npx)

npx [email protected]

Or pin in your MCP config

"command": "npx", "args": ["-y", "[email protected]", "--stdio"]
```

No config changes required. Existing dashboards continue to work - the new catalogs are purely additive.

Acknowledgments

Thanks for using mcp-dashboards. If it's useful to you, sponsorship buttons are at buymeacoffee.com/kyuish and github.com/sponsors/KyuRish.

Security Fixes

  • SSRF protection added to `render_from_url` and `poll_http` with DNS resolution blocking non‑unicast ranges; configurable via `MCP_URL_ALLOWLIST`
  • Per‑host outbound rate limiter (10 req/sec sustained, burst of 20, max 5 s wait) configurable via `MCP_OUTBOUND_RATE_PER_SEC` / `MCP_OUTBOUND_BURST`
  • HTTP server now binds to `127.0.0.1` by default; LAN access opt‑in via `MCP_HTTP_BIND_HOST=0.0.0.0`
  • CORS lockdown defaults to only `localhost`; configurable via `MCP_CORS_ALLOWED_ORIGINS`
  • `save_file` tool now restricts extensions to `.png` and `.csv` and hides files from the LLM
  • XSS sanitization added across hero, slope, waterfall, variance, bullet, dumbbell chart renderers using `sanitizeColor` / `escapeHtml` helpers
  • Preview‑server returns generic 500 errors (no filesystem leaks) and lazily cleans stale chart files
  • Inline JSON escape fixes premature termination caused by the literal space character

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track KyuRish/mcp-dashboards

Get notified when new releases ship.

Sign up free

About KyuRish/mcp-dashboards

45+ interactive chart types (bar, line, pie, candlestick, sankey, geo, radar, funnel, treemap, and more), dashboards with KPI cards, drill-down navigation, live API polling, 20 themes, and export to PNG/PPT/A4. Built on MCP Apps.

All releases →

Beta — feedback welcome: [email protected]