Skip to content

v1.5.4

Choose a tag to compare

@github-actions github-actions released this 19 Jul 00:15
· 118 commits to main since this release

Release v1.5.4

Release type: stable
Release line: 1.5.x
Branch: release/1.5.x

Installation

npm install @frontmcp/sdk@1.5.4

What's New

CHANGELOG

Features

  • Enhanced SSRF Protection: Introduced DNS-aware SSRF protection in the CIMD service, ensuring that every resolved address is validated against a private/reserved-range blocklist. This enhancement significantly reduces the risk of unauthorized internal access.
  • JWKS Fetch Improvements: Implemented a size cap and redirect limit for JWKS document fetching, enhancing security by preventing hostile bodies and excessive redirects.
  • Token Verification Enhancements: Added support for asymmetric JWS algorithms and issuer constraints, improving the security and flexibility of token verification processes.

Improvements

  • Authorization Code Handling: Updated the authorization store to record issued refresh tokens, enabling detection and handling of replay attacks more effectively.
  • Audience Validation: Refined audience validation logic to ensure stricter per-path binding, enhancing security for multi-tenant/multi-app hosts.

Bug Fixes

  • Open Redirect Prevention: Fixed an issue in the OAuth authorization flow where unvalidated redirect_uri could lead to open redirects, ensuring safer error handling and response.

Breaking Changes

  • Audience Validation Logic: Removed support for scheme-less host forms in audience validation, which may affect configurations relying on host-only audience binding. Users should configure expectedAudience explicitly for strict per-path binding.

🔒 Security

Huge thanks to @EQSTLab for responsibly disclosing GHSA-hvvp-67p3-j379 — a high-severity (CVSS 8.1) transparent-JWT authentication bypass in @frontmcp/auth/@frontmcp/sdk where the issuer and
audience claims weren't properly validated. The issue is now fixed, and their detailed report helped make FrontMCP more secure for everyone. 🙏

What's Changed

  • fix: refresh yarn.lock to match bumped versions after release versioning (#493) by @frontegg-david in #495
  • Cherry-pick: feat: add validation for package manifests and enhance SSRF protection in OpenAPI adapter by @github-actions[bot] in #497
  • Cherry-pick: feat: add lazy-aware JSON Schema conversion and regression tests for zod integration by @github-actions[bot] in #499
  • Cherry-pick: feat: implement ensureReady method for lazy bundle source initialization by @github-actions[bot] in #501
  • feat: enhance JWT verification with issuer validation and additional security checks by @frontegg-david in #502
  • Cherry-pick: fix: update Node.js version in .nvmrc to v24.18.0 by @github-actions[bot] in #504
  • Cherry-pick: feat: externalize @enclave-vm/core using enclaveCoreExactExternalPlugin and update dependencies to v2.15.0 by @frontegg-david in #507

Full Changelog: v1.5.3...v1.5.4