This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
Summary
AI summaryFixes incorrect handling of POSIX path backslashes and prevents false reporting of unrelated raw-data directories.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | High |
Update dependencies to address security advisories. Update dependencies to address security advisories. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fix scoped operations for POSIX paths containing backslashes. Fix scoped operations for POSIX paths containing backslashes. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Prevent unrelated `raw-data` directories from being reported as managed sources. Prevent unrelated `raw-data` directories from being reported as managed sources. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Improve CLI reliability when commands fail. Improve CLI reliability when commands fail. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Report the correct package version to MCP clients. Report the correct package version to MCP clients. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
- Fix scoped operations for POSIX paths containing backslashes.
- Prevent unrelated
raw-datadirectories from being reported as managed sources. - Improve CLI reliability when commands fail.
- Report the correct package version to MCP clients.
- Update dependencies to address security advisories.
Security Fixes
- Update dependencies to address security advisories
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About shinpr/mcp-local-rag
Privacy-first document search server running entirely locally. Supports semantic search over PDFs, DOCX, TXT, and Markdown files with LanceDB vector storage and local embeddings - no API keys or cloud services required.
Related context
Beta — feedback welcome: [email protected]