Skip to content

v3.51.1: security fixes for the pre-bash hook and MCP service destinations

Choose a tag to compare

@ruvnet ruvnet released this 02 Oct 16:19
· 627 commits to main since this release
09a1cb0

Security patch for @claude-flow/cli, claude-flow and ruflo (latest, alpha, v3alpha → 3.51.1). Upgrading is recommended.

PreToolUse pre-bash denials now block (#3623). When the hook handler recognised a denied command, it exited with status 1. Claude Code treats that as a non-blocking hook error, so the command could still run. Denials now exit 2, the status Claude Code's PreToolUse uses to block. The fix covers both shipped hook-handler.cjs copies and the handler ruflo init generates. Existing projects pick it up with npx ruflo@latest init upgrade (or a helper refresh).

MCP tools send credentials only to configured services (#3624). x_federation_* and seraphina_guidance read env-only credentials (RUFLO_X_ADMIN_TOKEN, SERAPHINA_METALLM_KEY). Their destinations are now pinned to the server-configured HTTPS base (RUFLO_X_GATEWAY_URL, SERAPHINA_METALLM_URL). A URL tool argument is only an assertion that must match that base; an absent, null or empty argument means no assertion. Every credential-bearing request rejects redirects. Operator configuration may name a loopback HTTP service for local or self-hosted gateways.

Verified: signed helper manifest at 3.51.1, witness manifests 117/117 on linux, macOS and Windows. A fresh npx ruflo@3.51.1 init writes the exit-2 handler.