Skip to content

Web Researcher MCP

v1.12.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai ai-agent anti-hallucination bibliography citation-verification claude
+13 more
claude-code claude-desktop content-extraction cursor fact-checking go llm mcp mcp-server model-context-protocol research web-scraping web-search

Affected surfaces

auth rbac crypto_tls

Summary

AI summary

Broad release touches @zoharbabin, Bug Fixes, Other, and Docker Images ```bash.

Full changelog

What's Changed

Full changelog: https://github.com/zoharbabin/web-researcher-mcp/compare/v1.11.0...v1.12.0

Changelog

New Features

  • 3e90473582989f97070babeab2213e27dab21ba4: feat(security): implement all critical & high compliance gaps (@zoharbabin)

Bug Fixes

  • 3770d0381e1dd1bca8648b388fb2979eb8615e17: fix(scraper): implement CHROME_PATH=disabled; make security e2e CI-deterministic (@zoharbabin)
  • fe1dd08f71b8d9734cc4ce6f35ba7bfdfea4ec69: fix(security): bound expiry-header allocation (CodeQL CWE-190 overflow) (@zoharbabin)
  • 1fa780a6eddc6b33d1c5dc49725f160ea6474749: fix(security): resolve all gosec findings with audited fixes (@zoharbabin)
  • ce5094a5890e38da1fd4c129a4fb4e4b3e8f3c12: fix: HTTP transport lifecycle + keyless zero-config startup (@zoharbabin)
  • 8f8545244caac65f5fbb56dacaae668617f0394d: fix: include all result-affecting params in search cache keys (@zoharbabin)
  • 4fdaabf058359293df1ca729d754b08cb7ed1826: fix: include max_length in scrape_page cache key (@zoharbabin)
  • ad6ef4086d16b20c3fef82701958026ab1d7bdfd: fix: resolve 6 correctness findings from live user-testing (@zoharbabin)
  • 18f542e7e0c8fa7e17661d0a163a82ad9b21a594: fix: track internal/cache/crypto.go; stop .gitignore shadowing the source pkg (@zoharbabin)

Other

  • 782b77200e97187eafda527def602040a8c64995: Merge PR #80: security, compliance, HTTP e2e, and v1.12.0 release prep (@zoharbabin)
  • ac03da926fd10c65c7c5a81532b4a32bb915b8fa: build: pin quality tools, harden CI, add pre-commit hook (@zoharbabin)
  • d927b7b4227e0d8dc04b4c03662c29aa19ec5cea: release: prepare v1.12.0 — bump version, fix lenses in release archives (@zoharbabin)
  • edaee6a10fce62d5531cbc4de4cd9aae104eb46f: test(e2e): HTTP transport + OAuth e2e coverage and Docker smoke test (@zoharbabin)
  • 98bfe185d208fb47b88a7198f56d7f00cb93d1cb: test(e2e): assert OAuth scope gate on its denial marker, not tool success (@zoharbabin)
  • 200597afc01580a0c4560ad23931948d5c7ea885: test(e2e): cover MCP Resources and Prompts (templates) over both transports (@zoharbabin)

Docker Images

# GitHub Container Registry
docker pull ghcr.io/zoharbabin/web-researcher-mcp:1.12.0

# Docker Hub
docker pull docker.io/zoharbabin/web-researcher-mcp:1.12.0

Homebrew

brew install zoharbabin/tap/web-researcher-mcp

Verify Checksums

sha256sum -c checksums.txt

Security Fixes

  • Bound expiry-header allocation to prevent CodeQL CWE-190 overflow
  • Resolved all gosec findings with audited security fixes

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Web Researcher MCP

Get notified when new releases ship.

Sign up free

About Web Researcher MCP

All releases →

Beta — feedback welcome: [email protected]