Skip to content

logly/mureo

v0.10.16 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

advertising agentic-ai ai-agents claude-code cli codex
+11 more
cursor facebook-ads gemini-cli google-ads marketing marketing-automation mcp meta-ads model-context-protocol python search-console

Affected surfaces

auth rce_ssrf

Summary

AI summary

Rollback no longer falsely reports success or double‑records failures.

Full changelog

Bug-fix release from a full-codebase audit (2 critical, 6 high, plus medium/low). No new features.

Highlights

  • Rollback no longer reports a failed reversal as applied (and no longer double-records it).
  • Credentials file is never wiped on a corrupt read (backup + refuse instead of resetting to {}).
  • Meta access-token auto-refresh now actually runs (was silently expiring at ~60 days).
  • Google Ads campaign listing no longer crashes on budgeted campaigns; Meta insights are no longer truncated to the first page.
  • Anomaly detection uses a non-overlapping prior window; the native MCP server no longer leaks HTTP connections.
  • SSRF-guarded outbound fetches, durable STATE.json writes, and assorted robustness fixes.

See CHANGELOG.md for the full list. PRs #354, #355.

Security Fixes

  • SSRF‑guarded outbound fetches

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track logly/mureo

Get notified when new releases ship.

Sign up free

About logly/mureo

Framework for AI agents (Claude Code, Cursor, Codex, Gemini) to operate Google Ads, Meta Ads, and Search Console. Grounded in a local STRATEGY.md — not metric-chasing. Defense-in-depth security, local-first. Apache 2.0.

All releases →

Related context

Beta — feedback welcome: [email protected]