This release includes 4 security fixes for security teams reviewing exposed deployments.
Topics
+9 more
Affected surfaces
Summary
AI summaryClosed symlink‑escape and flag‑bypass vulnerabilities and hardened federation SSRF handling.
Full changelog
Patch release carrying the 2026-07-05 pre-launch security review fixes.
Code hardening (#681): @tree symlink-escape (out-of-tree filename disclosure) closed; @tool --flag=value allow-list bypass closed; federation fetch/push SSRF-guarded (scheme + private-IP block + no-redirect); bounded LLM response reads.
Deploy/supply-chain posture (#682): Docker image no longer bakes PERSEUS_ALLOW_DANGEROUS=1 and runs non-root; bootstrap.sh installer repointed off the personal fork to the org namespace (+ optional version pin); pyyaml capped <7.
Full ranked review: docs/security-review-2026-07-05.md. Verified sound with no change: the @query/@agent double-gate, path containment, MCP SSE auth, build integrity, PyPI OIDC publishing.
Security Fixes
- @tree symlink-escape (out-of-tree filename disclosure) closed
- @tool --flag=value allow-list bypass closed
- Federation fetch/push now SSRF‑guarded (scheme + private‑IP block + no‑redirect)
- Bounded LLM response reads implemented
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About tcconnally/perseus](https:
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]