Skip to content

PreReason/mcp

v0.3.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 3mo MCP Data & Storage
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Affected surfaces

auth

Summary

AI summary

OAuth proxy endpoints hardened against input validation, rate limiting, and timeout issues.

Full changelog

Added

  • OAuth 2.1 support for automatic API key provisioning on MCP connection
  • Server branding metadata (title, description, icons) for client connection cards
  • Centered README hero layout with improved visual hierarchy

Security

  • Harden OAuth proxy endpoints with input validation, rate limiting, and timeout handling
  • Sanitize upstream error responses on token exchange

Fixed

  • HEAD /api/mcp returning 405 instead of 200
  • Metric count in README (38 -> 30)
  • cli.js version mismatch with package.json

Full Changelog: https://github.com/PreReason/mcp/compare/v0.2.1...v0.3.0

Security Fixes

  • Harden OAuth proxy endpoints with input validation, rate limiting, and timeout handling
  • Sanitize upstream error responses on token exchange

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track PreReason/mcp

Get notified when new releases ship.

Sign up free

About PreReason/mcp

Pre-reasoned Bitcoin and macro market briefings with trend signals, confidence scores, and regime classification. 17 briefings covering BTC, Fed balance sheet, M2, Treasury yields, and cross-asset correlations.

All releases →

Beta — feedback welcome: [email protected]