Skip to content

tcconnally/perseus](https:

v1.0.18 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

agent-memory ai-agents claude-code cli context-engine context-engineering
+9 more
hermes llm local-first mcp mcp-server model-context-protocol perseus python workspace-context

Affected surfaces

rce_ssrf deps

Summary

AI summary

Closed symlink‑escape and flag‑bypass vulnerabilities and hardened federation SSRF handling.

Full changelog

Patch release carrying the 2026-07-05 pre-launch security review fixes.

Code hardening (#681): @tree symlink-escape (out-of-tree filename disclosure) closed; @tool --flag=value allow-list bypass closed; federation fetch/push SSRF-guarded (scheme + private-IP block + no-redirect); bounded LLM response reads.

Deploy/supply-chain posture (#682): Docker image no longer bakes PERSEUS_ALLOW_DANGEROUS=1 and runs non-root; bootstrap.sh installer repointed off the personal fork to the org namespace (+ optional version pin); pyyaml capped <7.

Full ranked review: docs/security-review-2026-07-05.md. Verified sound with no change: the @query/@agent double-gate, path containment, MCP SSE auth, build integrity, PyPI OIDC publishing.

Security Fixes

  • @tree symlink-escape (out-of-tree filename disclosure) closed
  • @tool --flag=value allow-list bypass closed
  • Federation fetch/push now SSRF‑guarded (scheme + private‑IP block + no‑redirect)
  • Bounded LLM response reads implemented

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track tcconnally/perseus](https:

Get notified when new releases ship.

Sign up free

About tcconnally/perseus](https:

All releases →

Related context

Beta — feedback welcome: [email protected]