jevnav 0.1.13 — dependency security patch.
MCP Marketplace flagged five High CVEs in the mcp Python SDK, all of them in
versions the old mcp>=1.2 floor allowed. The floor is now mcp>=1.28.1, the
highest patched version among the advisories:
| Advisory | CVE | Affected | Patched |
|---|---|---|---|
| GHSA-3qhf-m339-9g5v | CVE-2025-53366 | < 1.9.4 | 1.9.4 |
| GHSA-j975-95f5-7wqh | CVE-2025-53365 | < 1.10.0 | 1.10.0 |
| GHSA-9h52-p55h-vw2f | CVE-2025-66416 | < 1.23.0 | 1.23.0 |
| GHSA-jpw9-pfvf-9f58 | CVE-2026-52869 | <= 1.27.1 | 1.27.2 |
| GHSA-vj7q-gjh5-988w | CVE-2026-59950 | < 1.28.1 | 1.28.1 |
No API changes. The lock stays on mcp 2.2.0 (full suite green); the new floor
was checked by hand at mcp==1.28.1 (MCP test files pass). server.json is
bumped alongside the package and a test now keeps the two versions in sync.