Skip to content

This release includes 4 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

adb agentic-ai android claude-code cursor mcp-server

Affected surfaces

deps

Summary

AI summary

CVE fixes in fastmcp and pytest resolve multiple vulnerabilities.

Full changelog

v0.5.1 (2026-04-13)

Bug Fixes

  • bump fastmcp and pytest to address known vulnerabilities
  • fastmcp >=3.2.0 resolves CVE-2026-32871, CVE-2026-27124, CVE-2025-64340
  • pytest >=9.0.3 resolves CVE-2025-71176
  • pip-audit added to dev dependencies
  • OpenSSF Scorecard workflow added, runs on every push to main

Security Fixes

  • dep: CVE-2026-32871 resolved by fastmcp >=3.2.0
  • dep: CVE-2026-27124 resolved by fastmcp >=3.2.0
  • dep: CVE-2025-64340 resolved by fastmcp >=3.2.0
  • dep: CVE-2025-71176 resolved by pytest >=9.0.3

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Neverlow512/agent-droid-bridge

Get notified when new releases ship.

Sign up free

About Neverlow512/agent-droid-bridge

MCP server giving AI agents programmatic control over Android devices and emulators via ADB. 11 tools covering UI inspection, screen interaction, ADB commands, and change detection.

All releases →

Beta — feedback welcome: [email protected]