This release fixes issues for SREs watching stability and regressions.
Published 1mo
LLM Frameworks
✓ No known CVEs patched
✓ No known CVEs patched in this version
Affected surfaces
rce_ssrf
Summary
AI summarySandbox mode files are now correctly bundled and --version reports the accurate version.
Full changelog
Highlights
- Sandbox mode silently disabled in 0.5.2 —
Dockerfile.sandboxandsandbox-entrypoint.shwere not bundled into the publishedmulmoclaudetarball, so onnpx mulmoclaudethe server loggedFailed to set up sandbox, running unrestrictedand fell back to unrestricted execution. Both files are now copied byprepare-dist.jsand listed infiles, and the publish-smoke CI asserts their presence in the packed tarball to prevent regressions. (#966) mulmoclaude --versionprinted stale0.5.1— the launcher had a hard-coded version string that drifted frompackage.json. Now matches the published version.
📦 npm: [email protected]
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About MulmoClaude
All releases →Related context
Related tools
Earlier breaking changes
- v0.6.4 `General` role split into lean `General` and new `Personal` role; Encore seed role pinned to Personal.
Beta — feedback welcome: [email protected]