This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 1mo
MCP Developer Tools
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
ai
ai-agent
anti-hallucination
bibliography
citation-verification
claude
+13 more
claude-code
claude-desktop
content-extraction
cursor
fact-checking
go
llm
mcp
mcp-server
model-context-protocol
research
web-scraping
web-search
Affected surfaces
auth
rbac
crypto_tls
Summary
AI summaryBroad release touches @zoharbabin, Bug Fixes, Other, and Docker Images ```bash.
Full changelog
What's Changed
Full changelog: https://github.com/zoharbabin/web-researcher-mcp/compare/v1.11.0...v1.12.0
Changelog
New Features
- 3e90473582989f97070babeab2213e27dab21ba4: feat(security): implement all critical & high compliance gaps (@zoharbabin)
Bug Fixes
- 3770d0381e1dd1bca8648b388fb2979eb8615e17: fix(scraper): implement CHROME_PATH=disabled; make security e2e CI-deterministic (@zoharbabin)
- fe1dd08f71b8d9734cc4ce6f35ba7bfdfea4ec69: fix(security): bound expiry-header allocation (CodeQL CWE-190 overflow) (@zoharbabin)
- 1fa780a6eddc6b33d1c5dc49725f160ea6474749: fix(security): resolve all gosec findings with audited fixes (@zoharbabin)
- ce5094a5890e38da1fd4c129a4fb4e4b3e8f3c12: fix: HTTP transport lifecycle + keyless zero-config startup (@zoharbabin)
- 8f8545244caac65f5fbb56dacaae668617f0394d: fix: include all result-affecting params in search cache keys (@zoharbabin)
- 4fdaabf058359293df1ca729d754b08cb7ed1826: fix: include max_length in scrape_page cache key (@zoharbabin)
- ad6ef4086d16b20c3fef82701958026ab1d7bdfd: fix: resolve 6 correctness findings from live user-testing (@zoharbabin)
- 18f542e7e0c8fa7e17661d0a163a82ad9b21a594: fix: track internal/cache/crypto.go; stop .gitignore shadowing the source pkg (@zoharbabin)
Other
- 782b77200e97187eafda527def602040a8c64995: Merge PR #80: security, compliance, HTTP e2e, and v1.12.0 release prep (@zoharbabin)
- ac03da926fd10c65c7c5a81532b4a32bb915b8fa: build: pin quality tools, harden CI, add pre-commit hook (@zoharbabin)
- d927b7b4227e0d8dc04b4c03662c29aa19ec5cea: release: prepare v1.12.0 — bump version, fix lenses in release archives (@zoharbabin)
- edaee6a10fce62d5531cbc4de4cd9aae104eb46f: test(e2e): HTTP transport + OAuth e2e coverage and Docker smoke test (@zoharbabin)
- 98bfe185d208fb47b88a7198f56d7f00cb93d1cb: test(e2e): assert OAuth scope gate on its denial marker, not tool success (@zoharbabin)
- 200597afc01580a0c4560ad23931948d5c7ea885: test(e2e): cover MCP Resources and Prompts (templates) over both transports (@zoharbabin)
Docker Images
# GitHub Container Registry
docker pull ghcr.io/zoharbabin/web-researcher-mcp:1.12.0
# Docker Hub
docker pull docker.io/zoharbabin/web-researcher-mcp:1.12.0
Homebrew
brew install zoharbabin/tap/web-researcher-mcp
Verify Checksums
sha256sum -c checksums.txt
Security Fixes
- Bound expiry-header allocation to prevent CodeQL CWE-190 overflow
- Resolved all gosec findings with audited security fixes
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Web Researcher MCP
All releases →Related context
Beta — feedback welcome: [email protected]