Skip to content

tcconnally/perseus](https:

v1.0.19 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent-memory ai-agents claude-code cli context-engine context-engineering
+9 more
hermes llm local-first mcp mcp-server model-context-protocol perseus python workspace-context

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Self‑update now requires a configured GPG fingerprint for unattended operation, and remote content in @perseus fences is treated as untrusted.

Full changelog

Patch release shipping the 2026-07-05 review housekeeping follow-ups (#684).

  • Self-update fails closed — unattended (update.auto) refuses without a configured update.gpg_fingerprint; a set fingerprint enforces a matching, valid signature. --skip-signature-check still bypasses.
  • @perseus fences remote content as untrusted DATA (blocks prompt-injection from a hostile/compromised peer).
  • Webhook empty-secret fails closed (no silent unsigned delivery).
  • serve rejects a missing Host on loopback binds (DNS-rebinding).
  • Vault-connector CWD binary search gated behind PERSEUS_DEV_VAULT_BUILD=1 (CWE-427).

See docs/security-review-2026-07-05.md.

Breaking Changes

  • Self‑update (`update.auto`) fails closed unless `update.gpg_fingerprint` is configured; a set fingerprint enforces matching, valid signature.

Security Fixes

  • Serve rejects missing Host header on loopback binds – mitigates DNS rebinding (CWE-427).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track tcconnally/perseus](https:

Get notified when new releases ship.

Sign up free

About tcconnally/perseus](https:

All releases →

Beta — feedback welcome: [email protected]