Skip to content

fix(security): mcp 1.29.0 and pydantic-settings 2.14.2 - #117

Merged
pamosima merged 1 commit into
mainfrom
fix/mcp-pydantic-settings-cves
Aug 4, 2026
Merged

fix(security): mcp 1.29.0 and pydantic-settings 2.14.2#117
pamosima merged 1 commit into
mainfrom
fix/mcp-pydantic-settings-cves

Conversation

@pamosima

@pamosima pamosima commented Aug 4, 2026

Copy link
Copy Markdown
Owner

Fixes remaining fixable Dependabot alerts in netops-mcp-server/uv.lock:

Not fixable yet: paramiko CVE-2026-44405 (low) — no patched release on PyPI beyond 4.0.0; monitor for Paramiko >4.0.0.

Made with Cursor

- mcp 1.26.0 -> 1.29.0 (>=1.28.1): CVE-2026-59950, CVE-2026-52869/52870
- pydantic-settings 2.13.1 -> 2.14.2: GHSA-4xgf-cpjx-pc3j

paramiko CVE-2026-44405 (low) has no PyPI release yet; stays at 4.0.0.

Co-authored-by: Cursor <cursoragent@cursor.com>
@pamosima
pamosima merged commit d83cf10 into main Aug 4, 2026
@pamosima
pamosima deleted the fix/mcp-pydantic-settings-cves branch August 4, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant