Skip to content

ndjordjevic/pinrag

v0.9.23 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 2mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

chromadb cursor discord github-repos langchain mcp
+8 more
mcp-server model-context-protocol pdf pypi python llm vscode youtube

Affected surfaces

deps

Summary

AI summary

Require pypdf ≥6.9.2 and requests ≥2.33.0 to address two published CVEs.

Full changelog

v0.9.23 — Security dependency updates

Patch release: bump pypdf and requests for published CVEs; refresh internal advertising strategy notes; minor repo hygiene.

Security

  • pypdf — Require ≥6.9.2 (CVE-2026-33699 / GHSA-87mj-5ggw-8qc3).
  • requests — Require ≥2.33.0 (CVE-2026-25645 / GHSA-gc5v-m9x4-r6x2).

Docs

  • Advertising — Notes updated for RepoClip promo video and checklist status.

Repo

  • Cursor — Project-level no-auto-git-commit-push rule removed (user-level rule in ~/.cursor/rules).

Security Fixes

  • dep: pypdf ≥6.9.2 — CVE-2026-33699 / GHSA-87mj-5ggw-8qc3
  • dep: requests ≥2.33.0 — CVE-2026-25645 / GHSA-gc5v-m9x4-r6x2

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track ndjordjevic/pinrag

Get notified when new releases ship.

Sign up free

About ndjordjevic/pinrag

RAG for PDFs, YouTube, GitHub repos, Discord exports; index documents and query with citations.

All releases →

Beta — feedback welcome: [email protected]