This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 9h
LLM Frameworks
✓ No known CVEs patched
This release patches 2 known CVEs
Affected surfaces
auth
rbac
Summary
AI summaryUpdates Highlights, fix, and refactor across a mixed release.
Full changelog
Highlights
- Validated dispatch arguments (#2594, #2603) —
isHtmlDispatchArgsandisPackHtmlArgsare now exported. Tool arguments arriving from outside were previously narrowed with uncheckedascasts, so a malformed payload reached the handler shaped as something it was not. The guards reject it at the boundary instead.
📦 npm: @mulmoclaude/[email protected]
What's Changed
- fix: polynomial ReDoS in the HTML attribute iterator (CodeQL #402) by @isamu in https://github.com/receptron/mulmoclaude/pull/2587
- perf(sessions): stop re-reading every session's meta on each list scan (#2588) by @isamu in https://github.com/receptron/mulmoclaude/pull/2589
- refactor: replace asyncHandler's Request/Response casts with structural bounds by @isamu in https://github.com/receptron/mulmoclaude/pull/2590
- fix: sanitise request-derived values reaching log.* (#2591) by @isamu in https://github.com/receptron/mulmoclaude/pull/2595
- refactor: replace 8 hand-rolled JsonObject casts in remoteHost handlers (#2592) by @isamu in https://github.com/receptron/mulmoclaude/pull/2596
- fix: forward next(err) from asyncHandler when headers are already sent (#2593) by @isamu in https://github.com/receptron/mulmoclaude/pull/2597
- chore(dev): make LAN exposure of the dev server opt-in by @isamu in https://github.com/receptron/mulmoclaude/pull/2599
- feat(calendar): Collection → Google Calendar push button (#2598) by @isamu in https://github.com/receptron/mulmoclaude/pull/2600
- fix: verify the loopback premise the CSRF guard was assuming by @isamu in https://github.com/receptron/mulmoclaude/pull/2601
- refactor: replace unvalidated
ascasts of external data with type guards (#2594) by @isamu in https://github.com/receptron/mulmoclaude/pull/2603
Full Changelog: https://github.com/receptron/mulmoclaude/compare/@mulmoclaude/[email protected]...@mulmoclaude/[email protected]
Security Fixes
- Fix: polynomial ReDoS in the HTML attribute iterator
- Fix: sanitise request-derived values reaching log.*
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About MulmoClaude
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]