Skip to content

MulmoClaude

v1.7.0 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 6h LLM Frameworks
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Affected surfaces

auth rbac

Summary

AI summary

Push to Google Calendar button adds two‑way sync for local records.

Full changelog

Superseded by v1.7.1. This tag marks the exact tree [email protected] was packed from, so the npm version keeps a traceable commit. It does not contain the icon fix (#2608), which merged twenty minutes after the publish — use 1.7.1.

Highlights

Push a collection back to Google Calendar (#2598)

A googleCalendar collection could only ever be filled from Google, and no setting enabled a write-back — which is why "two-way sync" could not be configured, and why the conversation with the agent went in circles: the thing being looked for did not exist.

The collection view gains a Push to Google button beside Sync. It creates events for records added locally and updates the fields actually edited, leaving attendees, reminders and recurrence untouched. It never deletes, and it skips a record edited on both sides rather than picking a winner.

Push before you sync — a pull overwrites a locally edited record as soon as Google reports any change to that event.

Also in this release

Self-service triage when something looks broken (#2571), the dev server no longer exposing your LAN by default (#2599), the CSRF guard verifying the loopback premise it was assuming (#2601), a log-injection sweep (#2591), type guards replacing unchecked casts on external data (#2592, #2594), a polynomial ReDoS fix (CodeQL #402), and a faster sessions list (#2588, #2584).

Full Changelog

See CHANGELOG.md.

Security Fixes

  • Polynomial ReDoS fixed (CodeQL #402)
  • Log‑injection vulnerabilities addressed (#2591)
  • CSRF guard now correctly verifies loopback premise (#2601)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track MulmoClaude

Get notified when new releases ship.

Sign up free

About MulmoClaude

All releases →

Related context

Earlier breaking changes

  • v1.1.1 Moves Google token store to ~/.config/mulmo/google-token.json
  • v0.6.4 `General` role split into lean `General` and new `Personal` role; Encore seed role pinned to Personal.

Beta — feedback welcome: [email protected]