Skip to content

fix(deps): fast-uri HIGH CVE + document get_aba_session_tracker#9

Merged
byteworthy merged 1 commit into
mainfrom
fix/fast-uri-cve
May 14, 2026
Merged

fix(deps): fast-uri HIGH CVE + document get_aba_session_tracker#9
byteworthy merged 1 commit into
mainfrom
fix/fast-uri-cve

Conversation

@byteworthy
Copy link
Copy Markdown
Collaborator

npm audit fix cleared fast-uri HIGH advisories (GHSA-q3j6-qgpj-74h6, GHSA-v39h-62p7-jpjc). Build + 9 tests pass. Documented previously-registered get_aba_session_tracker tool in README.

npm audit fix bumped fast-uri from <=3.1.1, clearing two HIGH
advisories (GHSA-q3j6-qgpj-74h6 path-traversal + GHSA-v39h-62p7-jpjc
host-confusion). Transitive through @modelcontextprotocol/sdk → ajv.
Build + 9 tests pass.

Also documented get_aba_session_tracker in README (Specialty
workflows). Implementation already existed; just missing from the
public tool table.

upstream-mcp now has 0 npm audit findings.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@byteworthy byteworthy merged commit 0d511c0 into main May 14, 2026
7 checks passed
@byteworthy byteworthy deleted the fix/fast-uri-cve branch May 14, 2026 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant