This release includes 5 security fixes for security teams reviewing exposed deployments.
Topics
+10 more
Affected surfaces
ReleasePort's take
Light signalScoped clients now lack metadata for renamed tools outside their profile; MCP servers no longer inherit Toolport control secrets; spawn screening blocks more bypasses.
Why it matters: Security‑focused changes (ids 67921‑67923) reduce privilege leakage and bypass risk. All three have severity 70, indicating high impact for developers, SREs, and security engineers monitoring metadata exposure, secret inheritance, or spawn evasion.
Summary
AI summaryUpdates Security and reliability, Highlights, and Upgrade across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Scoped clients no longer see metadata for renamed tools outside their profile. Scoped clients no longer see metadata for renamed tools outside their profile. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | High |
Spawned MCP servers no longer inherit Toolport control secrets. Spawned MCP servers no longer inherit Toolport control secrets. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | High |
Spawn screening now catches additional launcher, interpreter, remote-source, and wrapper bypasses. Spawn screening now catches additional launcher, interpreter, remote-source, and wrapper bypasses. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Choose discovery mode per client using `full`, `lazy`, or `grouped` options. Choose discovery mode per client using `full`, `lazy`, or `grouped` options. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
New Full-API catalog options added for Stripe, Vercel, Cloudflare, and Clerk. New Full-API catalog options added for Stripe, Vercel, Cloudflare, and Clerk. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Clear local activity data (audit, savings, inspection, search‑trace history) from Settings. Clear local activity data (audit, savings, inspection, search‑trace history) from Settings. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Gateway overload, long search queries, and oversized stdio frames are bounded. Gateway overload, long search queries, and oversized stdio frames are bounded. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Cross-process config writes are serialized so valid client state is not silently lost. Cross-process config writes are serialized so valid client state is not silently lost. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Install, repair, and uninstall remove stale duplicate Toolport gateway entries. Install, repair, and uninstall remove stale duplicate Toolport gateway entries. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Improves update handoff to the current gateway binary, desktop error recovery, Teams approval links, empty‑team onboarding, activity labels, and tool‑count messaging. Improves update handoff to the current gateway binary, desktop error recovery, Teams approval links, empty‑team onboarding, activity labels, and tool‑count messaging. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Toolport v1.8.0
More control per client, broader MCP coverage, and a safer gateway.
Highlights
- Choose discovery mode per client. Use
full,lazy, orgroupeddiscovery for each connected AI client without changing every other client. - Use broader official APIs. New Full-API catalog options are available for Stripe, Vercel, Cloudflare, and Clerk.
- Clear local activity data. Audit, savings, inspection, and search-trace history can now be removed together from Settings.
Security and reliability
- Scoped clients no longer see metadata for renamed tools outside their profile.
- Spawned MCP servers no longer inherit Toolport control secrets.
- Spawn screening now catches additional launcher, interpreter, remote-source, and wrapper bypasses.
- Gateway overload, long search queries, and oversized stdio frames are bounded.
- Cross-process config writes are serialized so valid client state is not silently lost.
- Install, repair, and uninstall remove stale duplicate Toolport gateway entries.
This release also improves update handoff to the current gateway binary, desktop error recovery, Teams approval links and empty-team onboarding, activity labels, and tool-count messaging.
Upgrade
- In-app: click the Toolport version in the sidebar footer when it shows an update.
- Installer: download the build for your platform below.
Contributors
Thank you to @sapunyangkut for improving tool-less Activity security notices, and to @tapheret2 for external-link guard regression coverage.
Security Fixes
- Scoped clients no longer see metadata for renamed tools outside their profile
- Spawned MCP servers no longer inherit Toolport control secrets
- Spawn screening now catches additional launcher, interpreter, remote-source, and wrapper bypasses
- Gateway overload, long search queries, and oversized stdio frames are bounded
- Cross‑process config writes are serialized to prevent silent loss of valid client state
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Toolport
All releases →Related context
Beta — feedback welcome: [email protected]