This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
Summary
AI summaryFixed stdio fallback to spawn local credential form instead of remote relay.
Full changelog
v2.26.1 (2026-04-21)
This release is published under the MIT License.
Bug Fixes
-
Accept SubjectContext arg on save_credentials (
6f56018) -
Hoist regex compilations to module-level for string processing performance (
86b0ea6) -
Pin fastmcp>=3.2.3,<4 to prevent Renovate downgrade to CVE-vulnerable 2.x (
424cec5) -
Stdio fallback spawns local credential form, not remote relay (
b9ec5a2) -
deps: Bump mcp-core to 1.4.3 (
326641f)
Detailed Changes: v2.26.0...v2.26.1
Security Fixes
- Prevent downgrade of fastmcp to CVE‑vulnerable 2.x by pinning fastmcp>=3.2.3,<4
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About n24q02m/wet-mcp
Web search (embedded SearXNG), content extraction, and library docs indexing with hybrid search (FTS5 + semantic). Built-in Qwen3 embedding, no API keys required.
Related context
Beta — feedback welcome: [email protected]