Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 24d MCP Search & Web
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Affected surfaces

auth

Summary

AI summary

Updates Verification, Security / correctness, and MCP extract safety across a mixed release.

Full changelog

Web Search Plus MCP v0.15.0

Syncs the standalone MCP package to the Web Search Plus v2.8.1 engine family.

Security / correctness

  • Harden authority-domain matching so look-alike domains no longer inherit canonical boosts.
  • Normalize corrupted gzip/deflate, non-UTF-8, invalid JSON, read interruption, socket timeout, and HTTP 429 Retry-After behavior into structured provider errors.

MCP extract safety

  • Add MCP-specific preview/store handling for oversized extraction payloads.
  • Large extracted text fields are bounded in MCP responses and full text is stored locally with stored_extract metadata.

Release hygiene

  • Derive DEFAULT_USER_AGENT from __version__, fixing the stale 0.13.0 User-Agent in v0.14.0.
  • Keep provider bench and Hermes standalone-plugin import fixes out of MCP by design.

Verification

  • 107 passed
  • ruff check . clean
  • compileall clean
  • wheel build clean

Security Fixes

  • Harden authority-domain matching so look‑alike domains no longer inherit canonical boosts

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track robbyczgw-cla/web-search-plus-mcp

Get notified when new releases ship.

Sign up free

About robbyczgw-cla/web-search-plus-mcp

Multi-provider web search with intelligent auto-routing (Serper, Tavily, Exa)

All releases →

Related context

Earlier breaking changes

  • v1.0.0 Native Perplexity and Kilo Perplexity answer endpoints removed from public provider schemas.
  • v1.0.0 Public search surface reduced to 12 verified source-result providers; extraction limited to 8 providers.
  • v0.5.1 kilo_perplexity renamed to kilo-perplexity without aliasing
  • v0.5.1 Perplexity provider separated from kilo-perplexity with distinct API keys

Beta — feedback welcome: [email protected]