Skip to content

v1.3.4 — Security fixes

Choose a tag to compare

@0xRaghu 0xRaghu released this 09 Apr 16:56
· 9 commits to main since this release

Security Fixes 🔒

Fixed CVE-2026-32285 (High severity)

Updated transitive dependencies to eliminate vulnerable github.com/buger/jsonparser v1.1.1:

  • github.com/mark3labs/mcp-go v0.43.2 → v0.47.1
  • github.com/mailru/easyjson v0.7.7 → v0.9.2

Impact: Prevents DoS via negative slice index panic
Closes: Dependabot alert #1

Removed unused HTTP proxy code

The experimental HTTP proxy had an authentication vulnerability where it read ANTHROPIC_API_KEY from environment and forwarded it with zero authentication, allowing any local process to consume API credits.

Since the proxy was never wired into the CLI and mnemo's architecture uses MCP server + hooks (not HTTP interception), we removed it entirely.

Closes: #5

Changes

  • CI: Updated golangci-lint workflow with --timeout=5m to prevent timeout failures

Full Changelog

v1.3.3...v1.3.4