Skip to content

Agent Security Scanner Mcp

v4.3.0 Security

This release includes 9 security fixes for security teams reviewing exposed deployments.

Published 2mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 9 known CVEs

Topics

agent-security ai-agent-security ai-security claude-code codex cursor
+14 more
hallucination-detection llm-security mcp mcp-security mcp-server openclaw owasp package-hallucination prompt-injection static-analysis security supply-chain-security vulnerability-scanning windsurf

Affected surfaces

auth rbac deps

Summary

AI summary

Broad release touches Security Updates, Bug Fixes, What Changed, and Testing.

Full changelog

🔒 Critical Security & Reliability Fixes

Security Updates

  • CRITICAL: Fix fail-open vulnerability in GitHub Actions that could bypass security gates (#71)
  • CRITICAL: Patch 8 Hono CVEs including XSS, path traversal, and authentication bypass (#75, #66, #65, #64, #62)
    • GHSA-69xw-7hcm-h432: HTML injection via unvalidated JSX tag names
    • GHSA-9vqf-7f2p-gf9v: bodyLimit() bypass for chunked requests
    • GHSA-458j-xx4x-4375: Improper JSX attribute name handling
    • GHSA-wmmm-f939-6g9c: Middleware bypass via repeated slashes
    • GHSA-xf4j-xp2r-rqqx: Path traversal in toSSG()
    • GHSA-xpcf-pg52-r92g: IPv4-mapped IPv6 address bypass
    • GHSA-26pp-8wgv-hjvm: Missing cookie name validation
    • GHSA-r5rp-j6wh-rvv4: Cookie prefix bypass

Bug Fixes

  • Fix confidence threshold filtering case sensitivity (#73)
  • Fix SARIF generation for GitHub Code Scanning (#72)

Dependencies

  • Update Hono 4.12.7 → 4.12.16
  • Update @hono/node-server to 1.19.13
  • Update Vite to 7.3.2
  • Update Lodash 4.17.23 → 4.18.1
  • Update PostCSS, path-to-regexp, picomatch

Testing

  • Add 18 new regression tests for critical fixes
  • All 420+ tests passing

⚠️ Upgrade recommended for production use.

See CHANGELOG.md for complete details.

Installation

npm install -g [email protected]

What Changed

  • 18 PRs merged (3 critical bug fixes + 15 security dependency updates)
  • 100% backward compatible
  • No breaking changes

Security Fixes

  • GHSA-69xw-7hcm-h432 — HTML injection via unvalidated JSX tag names (Hono CVE)
  • GHSA-9vqf-7f2p-gf9v — bodyLimit() bypass for chunked requests (Hono CVE)
  • GHSA-458j-xx4x-4375 — Improper JSX attribute name handling (Hono CVE)
  • GHSA-wmmm-f939-6g9c — Middleware bypass via repeated slashes (Hono CVE)
  • GHSA-xf4j-xp2r-rqqx — Path traversal in toSSG() (Hono CVE)
  • GHSA-xpcf-pg52-r92g — IPv4‑mapped IPv6 address bypass (Hono CVE)
  • GHSA-26pp-8wgv-hjvm — Missing cookie name validation (Hono CVE)
  • GHSA-r5rp-j6wh-rvv4 — Cookie prefix bypass (Hono CVE)
  • CRITICAL: Fix fail-open vulnerability in GitHub Actions that could bypass security gates

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Agent Security Scanner Mcp

Get notified when new releases ship.

Sign up free

About Agent Security Scanner Mcp

All releases →

Beta — feedback welcome: [email protected]