Repository navigation
v1.5.4
Release v1.5.4
Release type: stable
Release line: 1.5.x
Branch: release/1.5.x
Installation
npm install @frontmcp/sdk@1.5.4What's New
CHANGELOG
Features
- Enhanced SSRF Protection: Introduced DNS-aware SSRF protection in the CIMD service, ensuring that every resolved address is validated against a private/reserved-range blocklist. This enhancement significantly reduces the risk of unauthorized internal access.
- JWKS Fetch Improvements: Implemented a size cap and redirect limit for JWKS document fetching, enhancing security by preventing hostile bodies and excessive redirects.
- Token Verification Enhancements: Added support for asymmetric JWS algorithms and issuer constraints, improving the security and flexibility of token verification processes.
Improvements
- Authorization Code Handling: Updated the authorization store to record issued refresh tokens, enabling detection and handling of replay attacks more effectively.
- Audience Validation: Refined audience validation logic to ensure stricter per-path binding, enhancing security for multi-tenant/multi-app hosts.
Bug Fixes
- Open Redirect Prevention: Fixed an issue in the OAuth authorization flow where unvalidated
redirect_uricould lead to open redirects, ensuring safer error handling and response.
Breaking Changes
- Audience Validation Logic: Removed support for scheme-less host forms in audience validation, which may affect configurations relying on host-only audience binding. Users should configure
expectedAudienceexplicitly for strict per-path binding.
🔒 Security
Huge thanks to @EQSTLab for responsibly disclosing GHSA-hvvp-67p3-j379 — a high-severity (CVSS 8.1) transparent-JWT authentication bypass in @frontmcp/auth/@frontmcp/sdk where the issuer and
audience claims weren't properly validated. The issue is now fixed, and their detailed report helped make FrontMCP more secure for everyone. 🙏
What's Changed
- fix: refresh yarn.lock to match bumped versions after release versioning (#493) by @frontegg-david in #495
- Cherry-pick: feat: add validation for package manifests and enhance SSRF protection in OpenAPI adapter by @github-actions[bot] in #497
- Cherry-pick: feat: add lazy-aware JSON Schema conversion and regression tests for zod integration by @github-actions[bot] in #499
- Cherry-pick: feat: implement ensureReady method for lazy bundle source initialization by @github-actions[bot] in #501
- feat: enhance JWT verification with issuer validation and additional security checks by @frontegg-david in #502
- Cherry-pick: fix: update Node.js version in .nvmrc to v24.18.0 by @github-actions[bot] in #504
- Cherry-pick: feat: externalize @enclave-vm/core using enclaveCoreExactExternalPlugin and update dependencies to v2.15.0 by @frontegg-david in #507
Full Changelog: v1.5.3...v1.5.4