This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 5mo
MCP Security & Auth
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
agent-security
ai-agent-security
ai-security
claude-code
codex
cursor
+14 more
hallucination-detection
llm-security
mcp
mcp-security
mcp-server
openclaw
owasp
package-hallucination
prompt-injection
static-analysis
security
supply-chain-security
vulnerability-scanning
windsurf
Affected surfaces
rce_ssrf
deps
Summary
AI summaryUpdates 📦 Dependencies Updated, 🐛 Bug Fixes, and 🛠️ New Features across a mixed release.
Full changelog
🚀 What's New in v3.13.0
This release consolidates 8 dependency updates including critical security fixes and major performance improvements.
🔒 Security Fixes
- ajv 8.17.1 → 8.18.0 - Fixes CVE-2025-69873 (ReDoS attacks mitigation)
- @modelcontextprotocol/sdk 1.25.3 → 1.26.0 - Fixes GHSA-345p-7cg4-v4c7 (cross-client data leak)
⚡ Performance
- hono 4.11.7 → 4.12.1 - 1.5x-2x faster router performance via trie-router optimization
- AJV tree-shaking - Smaller bundle sizes with
sideEffects: false
📦 Dependencies Updated
hono: 4.11.7 → 4.12.1 (main + mcp-server-full)ajv: 8.17.1 → 8.18.0 (main + mcp-server-full)qs: 6.14.1 → 6.15.0 (main + mcp-server-full)@modelcontextprotocol/sdk: 1.25.3 → 1.26.0 (main + mcp-server-full)
🛠️ New Features
- Hono:
$path()method for client,ApplyGlobalResponsetype helper - QS:
strictMergeoption for object/primitive conflicts - MCP SDK: OAuth client credentials scopes support
🐛 Bug Fixes
- AJV: Infinity and NaN serialization to null
- QS:
duplicatesoption handling for bracket notation - MCP SDK: npm audit vulnerabilities resolved
📥 Installation
npm install -g agent-security-scanner-mcp@latest
🔗 Links
- Full Changelog: https://github.com/sinewaveai/agent-security-scanner-mcp/compare/v3.12.0...v3.13.0
- npm Package: https://www.npmjs.com/package/agent-security-scanner-mcp
- MCP Registry: https://registry.modelcontextprotocol.io/
All 8 PRs merged: #4, #9, #10, #11, #13, #14, #17, #18
Tests: 419 passed
Breaking Changes: None - fully backward compatible
Security Fixes
- CVE-2025-69873 — ajv ReDoS attacks mitigation (ajv 8.17.1 → 8.18.0)
- GHSA-345p-7cg4-v4c7 — @modelcontextprotocol/sdk cross-client data leak fix (@modelcontextprotocol/sdk 1.25.3 → 1.26.0)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Agent Security Scanner Mcp
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]