Skip to content

This release fixes issues for SREs watching stability and regressions.

Published 3mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai automation browser-automation claude google llm
+5 more
mcp model-context-protocol notebooklm research typescript

Affected surfaces

auth

Summary

AI summary

Fixed bug where cleanup_data(confirm:true) deleted Google auth credentials, causing authentication failures.

Full changelog

Critical Bug Fix

Root Cause

Sessions were following get_health's troubleshooting tip which said to run cleanup_data(confirm:true). This deleted browser_state/ and chrome_profile/ — the Google auth credentials — then setup_auth ran headlessly and failed to restore them.

Changes

  • cleanup_data no longer includes browser_state or chrome_profile in any cleanup path — these contain Google auth cookies that require interactive login to recreate
  • get_health troubleshooting tip updated to say setup_auth(show_browser:true) and explicitly warns not to call cleanup_data for auth issues

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Pantheon-Security/notebooklm-mcp-secure

Get notified when new releases ship.

Sign up free

About Pantheon-Security/notebooklm-mcp-secure

Security-hardened NotebookLM MCP with post-quantum encryption (ML-KEM-768), GDPR/SOC2/CSSF compliance, and 14 security layers. Query Google's Gemini-grounded research from Claude and AI agents.

All releases →

Beta — feedback welcome: [email protected]