This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
Summary
AI summaryResolved XSS vulnerability in textToHtml.
Full changelog
v1.3.0 (2026-03-06)
Bug Fixes
-
Fix Codecov badge in README (
317931b) -
security: Resolve code scanning alerts and XSS in textToHtml (
046ef8f)
Chores
Features
- Add comprehensive Phase 5 live test via MCP protocol (
95f6af6)
Detailed Changes: v1.2.5...v1.3.0
Security Fixes
- Resolved XSS vulnerability in textToHtml
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About n24q02m/better-email-mcp
IMAP/SMTP email MCP server with App Passwords (no OAuth2). Auto-discovers Gmail, Outlook, Yahoo, iCloud. 5 composite tools: search, read, send, reply, forward. Multi-account support.
Related context
Beta — feedback welcome: [email protected]