Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions .changeset/security-audit-verification.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
"mcp-taskflow": patch
---

Security: Fix high-severity vulnerabilities via pnpm overrides

Added pnpm overrides to fix security vulnerabilities:

1. **tar <= 7.5.6** (6 high severity issues):
- Arbitrary File Overwrite and Symlink Poisoning
- Race Condition via Unicode Ligature Collisions
- Arbitrary File Creation/Overwrite via Hardlink Path Traversal
- Enforced tar >= 7.5.7 via pnpm override

2. **@modelcontextprotocol/sdk** (2 high severity CVEs):
- CVE-2026-0621: Regular Expression Denial of Service (ReDoS) vulnerability (CVSS 8.7)
- CVE-2026-25536: Cross-Client Data Leak via shared server/transport instance (CVSS 7.1)
- Enforced @modelcontextprotocol/sdk >= 1.26.0 via pnpm override

3. **axios <= 1.13.4** (1 high severity):
- GHSA-43fc-jf86-j433: Denial of Service via __proto__ Key in mergeConfig
- Enforced axios >= 1.13.5 via pnpm override

Changes:
- Added `tar: "^7.5.7"` to pnpm.overrides in package.json
- Added `@modelcontextprotocol/sdk: ">=1.26.0"` to pnpm.overrides in package.json
- Added `axios: ">=1.13.5"` to pnpm.overrides in package.json
- Updated pnpm-lock.yaml with security fixes
- Added package-lock.json to .gitignore (pnpm-only repository)

All 593 tests pass.
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# Dependencies
node_modules/
.pnpm-store/
package-lock.json

# Build output
dist/
Expand Down
4 changes: 3 additions & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,9 @@
},
"pnpm": {
"overrides": {
"tar": "^7.5.7"
"tar": "^7.5.7",
"@modelcontextprotocol/sdk": ">=1.26.0",
"axios": ">=1.13.5"
}
}
}
12 changes: 7 additions & 5 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading