Repository navigation
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-20574183 - https://snyk.io/vuln/SNYK-JS-MODELCONTEXTPROTOCOLSDK-20579853
|
This update includes a medium-risk change for @modelcontextprotocol/sdk 1.29.0 → 1.31.0 (Medium Risk) This minor version upgrade introduces a significant behavioral change in how servers handle connections. As of version 1.31.0, a Action required: Applications that reuse a single server object or a stateless transport for multiple HTTP requests will fail after the second request. The code must be updated to create a new server and transport for each incoming request. handlebars 4.7.9 → 4.7.10 (Low Risk) This is a patch release that addresses two critical remote code execution (RCE) vulnerabilities (CVE-2026-106445, CVE-2026-106446). There are no documented breaking API changes for standard usage. The fixes target unintended use-cases related to prototype access and are not expected to impact applications following documented practices. Source: Release notes
|
Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
core/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-HANDLEBARS-20574183
SNYK-JS-MODELCONTEXTPROTOCOLSDK-20579853
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Access of Resource Using Incompatible Type ('Type Confusion')