fix: upgrade fastmcp to 3.2.0 to fix SSRF vulnerability (CVE) - #12516
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release-1.9.0 #12516 +/- ##
=================================================
+ Coverage 50.05% 50.09% +0.03%
=================================================
Files 1930 1932 +2
Lines 172591 172025 -566
Branches 25234 24158 -1076
=================================================
- Hits 86398 86175 -223
+ Misses 85147 84804 -343
Partials 1046 1046
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
security: upgrade fastmcp to 3.2.0 to fix SSRF vulnerability (CVE) Co-authored-by: Janardan S Kavia <janardanskavia@Janardans-MacBook-Pro.local>
Security Fix Details
Package: fastmcp
Vulnerable Version: < 3.2.0
Fixed Version: 3.2.0
Vulnerability: Authenticated SSRF via path traversal in OpenAPIProvider
Impact: Attackers could escape API prefix and access arbitrary backend endpoints
JIRA: https://datastax.jira.com/browse/LE-771
Depbotscan:
https://github.com/langflow-ai/langflow/security/dependabot/691
https://github.com/langflow-ai/langflow/security/dependabot/690