This release includes 1 security fix for security teams reviewing exposed deployments.
Published 8h
LLM Frameworks
✓ No known CVEs patched
This release patches 1 known CVE
Affected surfaces
auth
rbac
Summary
AI summaryUpdates Highlights, fix, and refactor across a mixed release.
Full changelog
Highlights
- Validated dispatch arguments (#2594, #2603) —
isMarkdownDispatchArgsis now exported, replacing an uncheckedascast of externally supplied tool arguments with a real runtime guard.
📦 npm: @mulmoclaude/[email protected]
What's Changed
- fix: polynomial ReDoS in the HTML attribute iterator (CodeQL #402) by @isamu in https://github.com/receptron/mulmoclaude/pull/2587
- perf(sessions): stop re-reading every session's meta on each list scan (#2588) by @isamu in https://github.com/receptron/mulmoclaude/pull/2589
- refactor: replace asyncHandler's Request/Response casts with structural bounds by @isamu in https://github.com/receptron/mulmoclaude/pull/2590
- fix: sanitise request-derived values reaching log.* (#2591) by @isamu in https://github.com/receptron/mulmoclaude/pull/2595
- refactor: replace 8 hand-rolled JsonObject casts in remoteHost handlers (#2592) by @isamu in https://github.com/receptron/mulmoclaude/pull/2596
- fix: forward next(err) from asyncHandler when headers are already sent (#2593) by @isamu in https://github.com/receptron/mulmoclaude/pull/2597
- chore(dev): make LAN exposure of the dev server opt-in by @isamu in https://github.com/receptron/mulmoclaude/pull/2599
- feat(calendar): Collection → Google Calendar push button (#2598) by @isamu in https://github.com/receptron/mulmoclaude/pull/2600
- fix: verify the loopback premise the CSRF guard was assuming by @isamu in https://github.com/receptron/mulmoclaude/pull/2601
- refactor: replace unvalidated
ascasts of external data with type guards (#2594) by @isamu in https://github.com/receptron/mulmoclaude/pull/2603
Full Changelog: https://github.com/receptron/mulmoclaude/compare/@mulmoclaude/[email protected]...@mulmoclaude/[email protected]
Security Fixes
- Fix: polynomial ReDoS vulnerability in HTML attribute iterator (CodeQL #402)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About MulmoClaude
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]