Skip to content

r33drichards/mcp-js

v0.14.0 Feature

This release adds 2 notable features for engineering teams evaluating rollout.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

javascript mcp mcp-server

Affected surfaces

rce_ssrf

Summary

AI summary

Added file upload support for /api/exec and run_js file‑path reads

Changes in this release

Feature Low

Adds file upload support to /api/exec endpoint

Adds file upload support to /api/exec endpoint

Source: llm_adapter@2026-06-14

Confidence: high

Feature Low

Enables run_js to read files via file-path parameter

Enables run_js to read files via file-path parameter

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Full changelog

What's Changed

  • Add file upload support to /api/exec and run_js file-path reads by @r33drichards in https://github.com/r33drichards/mcp-js/pull/167

Full Changelog: https://github.com/r33drichards/mcp-js/compare/v.0.13.0...v0.14.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track r33drichards/mcp-js

Get notified when new releases ship.

Sign up free

About r33drichards/mcp-js

A Javascript code execution sandbox that uses v8 to isolate code to run AI generated javascript locally without fear. Supports heap snapshotting for persistent sessions.

All releases →

Related context

Earlier breaking changes

  • v0.12.0 Removes /api/tools endpoint.
  • v0.11.0 Switch license from ISC to GNU Affero General Public License v3

Beta — feedback welcome: [email protected]