Skip to content

This release fixes issues for SREs watching stability and regressions.

Published 20d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

llm mcp mcp-server vibe-coding

Affected surfaces

auth

Summary

AI summary

Skips internal IP ranges when extracting client IP from X-Forwarded-For.

Full changelog

Patch Changes

  • 41878ec: Skip loopback (127.0.0.0/8), link-local (169.254.0.0/16), CGNAT (100.64.0.0/10), IPv6 loopback (::1), IPv6 link-local (fe80::/10), and IPv6 unique-local (fc00::/7) addresses when extracting the client IP from X-Forwarded-For, so proxy-internal hops no longer pollute the reported client IP.
  • 33229cb: Clarify the query-docs query description so it asks for a single concept per query. When a question spans multiple distinct topics, callers are now told to make a separate query per concept instead of combining them (unless the question is about how the concepts interact), which avoids diluted, shallow results. Applied consistently across the MCP server, CLI, pi, and AI SDK tools.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track upstash/context7

Get notified when new releases ship.

Sign up free

About upstash/context7

Up-to-date code documentation for LLMs and AI code editors.

All releases →

Related context

Earlier breaking changes

  • [email protected] Removes `--device` flag and localhost-callback path for `ctx7 login`.

Beta — feedback welcome: [email protected]