This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 2mo
MCP Developer Tools
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
chromadb
cursor
discord
github-repos
langchain
mcp
+8 more
mcp-server
model-context-protocol
pdf
pypi
python
llm
vscode
youtube
Affected surfaces
deps
Summary
AI summaryRequire pypdf ≥6.9.2 and requests ≥2.33.0 to address two published CVEs.
Full changelog
v0.9.23 — Security dependency updates
Patch release: bump pypdf and requests for published CVEs; refresh internal advertising strategy notes; minor repo hygiene.
Security
- pypdf — Require ≥6.9.2 (CVE-2026-33699 / GHSA-87mj-5ggw-8qc3).
- requests — Require ≥2.33.0 (CVE-2026-25645 / GHSA-gc5v-m9x4-r6x2).
Docs
- Advertising — Notes updated for RepoClip promo video and checklist status.
Repo
- Cursor — Project-level
no-auto-git-commit-pushrule removed (user-level rule in~/.cursor/rules).
Security Fixes
- dep: pypdf ≥6.9.2 — CVE-2026-33699 / GHSA-87mj-5ggw-8qc3
- dep: requests ≥2.33.0 — CVE-2026-25645 / GHSA-gc5v-m9x4-r6x2
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About ndjordjevic/pinrag
RAG for PDFs, YouTube, GitHub repos, Discord exports; index documents and query with citations.
Related context
Beta — feedback welcome: [email protected]