This repository was archived by the owner on Aug 26, 2026. It is now read-only.
Releases: hoyt-harness/ProcExecMCP
Releases · hoyt-harness/ProcExecMCP
Release list
v1.0.5
Full Changelog: v1.0.4...v1.0.5
v1.0.4
Changes
- chore(deps): bump nltk from 3.9.4 to 3.10.0 (f0ebf00)
Security
Resolves 5 high-severity vulnerabilities in the nltk transitive dependency (via safety):
- CVE-2026-54293: URL-encoded path traversal in nltk.data.load()
- CVE-2026-12072: Path traversal in NKJPCorpusReader
- CVE-2026-12074: Path traversal in FramenetCorpusReader
- CVE-2026-12061: ReDoS in ReviewsCorpusReader FEATURES regex
- CVE-2026-12075: DNS-rebinding SSRF filter bypass in nltk.pathsec
Also adds defusedxml 0.7.1 as a new transitive dependency (XML entity expansion protection introduced by nltk 3.10.0).
Note: cryptography CVE-2026-69247 (PR #3) is deferred pending soak window — re-evaluate 2026-08-12.