This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
Affected surfaces
Summary
AI summaryAdded file upload support for /api/exec and run_js file‑path reads
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds file upload support to /api/exec endpoint Adds file upload support to /api/exec endpoint Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Enables run_js to read files via file-path parameter Enables run_js to read files via file-path parameter Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
Full changelog
What's Changed
- Add file upload support to /api/exec and run_js file-path reads by @r33drichards in https://github.com/r33drichards/mcp-js/pull/167
Full Changelog: https://github.com/r33drichards/mcp-js/compare/v.0.13.0...v0.14.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About r33drichards/mcp-js
A Javascript code execution sandbox that uses v8 to isolate code to run AI generated javascript locally without fear. Supports heap snapshotting for persistent sessions.
Related context
Related tools
Beta — feedback welcome: [email protected]