Repository navigation
v1.3.4 — Security fixes
Security Fixes 🔒
Fixed CVE-2026-32285 (High severity)
Updated transitive dependencies to eliminate vulnerable github.com/buger/jsonparser v1.1.1:
github.com/mark3labs/mcp-gov0.43.2 → v0.47.1github.com/mailru/easyjsonv0.7.7 → v0.9.2
Impact: Prevents DoS via negative slice index panic
Closes: Dependabot alert #1
Removed unused HTTP proxy code
The experimental HTTP proxy had an authentication vulnerability where it read ANTHROPIC_API_KEY from environment and forwarded it with zero authentication, allowing any local process to consume API credits.
Since the proxy was never wired into the CLI and mnemo's architecture uses MCP server + hooks (not HTTP interception), we removed it entirely.
Closes: #5
Changes
- CI: Updated golangci-lint workflow with
--timeout=5mto prevent timeout failures