This release includes 1 security fix for security teams reviewing exposed deployments.
Published 3mo
MCP Developer Tools
✓ No known CVEs patched
This release patches 1 known CVE
Topics
mcp
mcp-framework
mcp-server
model-context-protocol
Affected surfaces
rce_ssrf
Summary
AI summaryFixed unhandled rejection crash in SSE server template.
Full changelog
Fixed
- SSE server template now wraps the async HTTP handler body in
try/catch- prevents unhandled rejection crash scaffold()now cleans up the target directory on partial write failure - prevents orphaned broken project filesfusion deploynow prompts before auto-installingesbuild- no longer silently modifies package.jsonfusion deployvalidatesserverIdformat and appliesencodeURIComponent- prevents path traversalFusionClientaccepts adiscriminatorKeyoption (defaults toaction) - supports custom server discriminators
Security Fixes
- `fusion deploy` validates `serverId` format and applies `encodeURIComponent` – prevents path traversal
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About vinkius-labs/mcp-fusion
A TypeScript framework for building production-ready MCP servers with automatic tool discovery, multi-transport support (stdio/SSE/HTTP), built-in validation, and zero-config setup.
Related context
Related tools
Beta — feedback welcome: [email protected]