Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

blackmagic blackmagic-design blackmagicdesign davinci-resolve davinciresolve mcp
+1 more
mcp-server

Affected surfaces

rce_ssrf breaking_upgrade

Summary

AI summary

apply_spec hooks no longer run with shell=True, preventing arbitrary shell injection.

Full changelog

v2.54.5

Reliability + security hardening from the exhaustive reliability audit (Wave A).

Security

  • apply_spec hooks no longer run with shell=True. A spec's hook command is now
    shlex-split and executed without a shell, so a hook string can't inject
    arbitrary shell (; rm -rf …, pipes, expansion). Hooks needing shell features
    must invoke an interpreter explicitly (e.g. bash -c "…").

Fixed

  • The confirm-token table is now guarded by a lock. The control panel is threaded,
    so issue/consume/GC ran concurrently; validate-then-pop is now atomic and GC
    can't race a write.
  • Negative item indices are rejected instead of silently returning the wrong item
    (_get_item, audio item resolver, the two timeline-matte helpers).
  • History queries clamp limit to [1, 1000] — SQLite treats a negative LIMIT
    as "no limit", so a negative value could silently fetch the whole table.
    timeline_versioning version/limit/keep_n params are validated (no unhandled
    ValueError; rollback rejects negative versions before archiving). The relink
    file search clamps max_files/max_seconds positive.
  • The server-reachable ffmpeg probes (render/audio/review) pass timeout=120, so a
    hung ffmpeg can't block the server indefinitely.

Validation

  • Full offline unit/static suite green (1264 tests; new tests/test_exhaustive_wave_a.py).
    All changes are defensive guards on invalid input or internal concurrency — no
    behavior change for valid inputs and no Resolve mutation semantics changed, so no
    live run required.

Deferred to a live-validated follow-up

  • Confirm-token gating + version-on-mutate archiving for catastrophic media-pool /
    take / Fusion-comp deletes (a destructive-action registry name mismatch currently
    bypasses governance), and temp-directory lifecycle cleanup.

Security Fixes

  • `apply_spec` hooks now split command strings with shlex and execute without a shell, eliminating arbitrary shell injection vulnerability (e.g., `; rm -rf …`). Hooks requiring shell features must invoke an interpreter explicitly (e.g., `bash -c "…"`).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track samuelgursky/davinci-resolve-mcp

Get notified when new releases ship.

Sign up free

About samuelgursky/davinci-resolve-mcp

MCP server integration for DaVinci Resolve

All releases →

Beta — feedback welcome: [email protected]