This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 3mo
MCP Data & Storage
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
ai-agents
ai-coding
claude
claude-code
cursor
docker
+7 more
email
imap
mcp
mcp-server
model-context-protocol
smtp
typescript
Affected surfaces
crypto_tls
auth
Summary
AI summaryEnforced SMTP TLS and fixed XSS vulnerabilities.
Full changelog
v1.2.3 (2026-03-03)
Bug Fixes
- security: Enforce SMTP TLS, prevent XSS, remove unused zod dep, DRY refactor, boost test coverage to 98% (#112,
42a7011)
Detailed Changes: v1.2.2...v1.2.3
Security Fixes
- Enforced SMTP TLS encryption for all outbound connections, preventing cleartext transmission.
- Fixed XSS vulnerability in email processing components.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About n24q02m/better-email-mcp
IMAP/SMTP email MCP server with App Passwords (no OAuth2). Auto-discovers Gmail, Outlook, Yahoo, iCloud. 5 composite tools: search, read, send, reply, forward. Multi-account support.
Related context
Beta — feedback welcome: [email protected]