Skip to content

fix(deps): upgrade mcp 1.27.1 -> 1.28.1 (CVE-2026-52869) - #835

Merged
manavgup merged 1 commit into
mainfrom
fix/cve-mcp-bump
Jul 19, 2026
Merged

fix(deps): upgrade mcp 1.27.1 -> 1.28.1 (CVE-2026-52869)#835
manavgup merged 1 commit into
mainfrom
fix/cve-mcp-bump

Conversation

@manavgup

Copy link
Copy Markdown
Owner

Problem

CVE-2026-52869 (HIGH) against mcp 1.27.1 was published to the Trivy vulnerability DB after #833 passed on July 16. Result: main's post-merge Docker build failed the CVE scan (so the #833 deploy was skipped — production is untouched), and PR #832's rebased checks fail on the same finding.

Solution

Lockfile-only bump: mcp 1.27.1 → 1.28.1 (covers the 1.27.2 fix). make verify passes locally: 2134 tests, all checks green.

Notes

🤖 Generated with Claude Code

CVE-2026-52869 (HIGH, fixed in 1.27.2) was published after #833 went
green, failing the Trivy scan on main's post-merge Docker build — which
skipped the deploy — and on PR #832's rebased checks. Lockfile-only
bump; full verify passes (2134 tests).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@manavgup
manavgup merged commit 6f95214 into main Jul 19, 2026
11 checks passed
@manavgup
manavgup deleted the fix/cve-mcp-bump branch July 19, 2026 14:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant