This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 8h
LLM Frameworks
✓ No known CVEs patched
This release patches 2 known CVEs
Affected surfaces
auth
rbac
Summary
AI summaryUpdates Highlights, fix, and refactor across a mixed release.
Full changelog
Highlights
- Typed HTTP helpers (#2590) —
ErrorBodyandApiResponse<T>are now exported, andasyncHandlertakes structural bounds (RoutePathBearing/ErrorSendableResponse) instead of casting itsRequest/Responsegenerics. A handler whose response type cannot carry an error body is now a compile error rather than a runtime surprise.
📦 npm: @mulmoclaude/[email protected]
What's Changed
- fix: polynomial ReDoS in the HTML attribute iterator (CodeQL #402) by @isamu in https://github.com/receptron/mulmoclaude/pull/2587
- perf(sessions): stop re-reading every session's meta on each list scan (#2588) by @isamu in https://github.com/receptron/mulmoclaude/pull/2589
- refactor: replace asyncHandler's Request/Response casts with structural bounds by @isamu in https://github.com/receptron/mulmoclaude/pull/2590
- fix: sanitise request-derived values reaching log.* (#2591) by @isamu in https://github.com/receptron/mulmoclaude/pull/2595
- refactor: replace 8 hand-rolled JsonObject casts in remoteHost handlers (#2592) by @isamu in https://github.com/receptron/mulmoclaude/pull/2596
- fix: forward next(err) from asyncHandler when headers are already sent (#2593) by @isamu in https://github.com/receptron/mulmoclaude/pull/2597
- chore(dev): make LAN exposure of the dev server opt-in by @isamu in https://github.com/receptron/mulmoclaude/pull/2599
- feat(calendar): Collection → Google Calendar push button (#2598) by @isamu in https://github.com/receptron/mulmoclaude/pull/2600
- fix: verify the loopback premise the CSRF guard was assuming by @isamu in https://github.com/receptron/mulmoclaude/pull/2601
- refactor: replace unvalidated
ascasts of external data with type guards (#2594) by @isamu in https://github.com/receptron/mulmoclaude/pull/2603
Full Changelog: https://github.com/receptron/mulmoclaude/compare/@mulmoclaude/[email protected]...@mulmoclaude/[email protected]
Security Fixes
- Fix polynomial ReDoS in the HTML attribute iterator (CodeQL #402)
- Sanitise request-derived values reaching log.* (#2591)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About MulmoClaude
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]