This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
Summary
AI summarySanitize signal connection parameters to prevent scene file injection.
Full changelog
v1.13.0 (2026-04-19)
Bug Fixes
-
Apply biome format across test files for CI parity (#517,
bf33be0) -
Refactor handleNodes into specialized handlers (#499,
0d0ba04) -
Sanitize signal connection parameters to prevent scene file injection (#498,
97654de) -
Untrack .jules + docs/superpowers AI traces from public repo (
6556c63) -
Update test mocks for fstatSync after chunked-scan refactor (#517,
bf33be0) -
detector: FstatSync, fix test mocks, add preview/beta binary names and paths (#487,
2d837b9) -
detector: Skip signature heuristic for explicit paths, add overlap to chunked scan (#487,
2d837b9) -
helpers: Refactor parseSceneContent for better maintainability (#508,
84184d9) -
physics: [SECURITY] prevent scene file injection via physics properties (#493,
778c8cd) -
security: Prevent argument injection in Godot CLI execution (#504,
b1cd0a6)
Chores
-
deps: Update actions/create-github-app-token digest to 1b10c78 (#513,
d612d95) -
deps: Update step-security/harden-runner digest to 6c3c2f2 (#514,
320d91c)
Features
-
Add MCP protocol E2E tests for stdio and HTTP transports (
87404c3) -
Add setup_* no-op actions to config tool for 7-repo parity (#517,
bf33be0) -
detector: Add head/tail fast path before full chunked scan (#487,
2d837b9)
Performance Improvements
Refactoring
Testing
-
Add unit tests for launchGodotEditor and runGodotProject (#507,
3204efc) -
godot: Add coverage for tryGetVersion and isLikelyGodotBinary (#501,
167c301)
Detailed Changes: v1.12.2...v1.13.0
Security Fixes
- [#498] Sanitize signal connection parameters to prevent scene file injection
- [#493] Prevent scene file injection via physics properties
- [#504] Prevent argument injection in Godot CLI execution
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About n24q02m/better-godot-mcp
18 composite tools for structured Godot 4.x interaction: scenes, nodes, GDScript, shaders, animation, tilemap, physics, audio, navigation, UI, input mapping, and signals.
Related context
Beta — feedback welcome: [email protected]