github wonderwhy-er/DesktopCommanderMCP v0.2.33
# Release Notes - v0.2.33

latest releases: v0.2.38, v0.2.37, v0.2.36...
one month ago

Security

  • Fix command blocklist bypass via absolute paths and command substitution — thanks @dcpagotto
  • validatePath now blocks symlink traversal to prevent arbitrary read/write — thanks @zjyhhhher
  • Added symlink security tests for validatePath

Protocol

  • Use SDK protocol version negotiation instead of a hardcoded version (found and suggested by @abcnow)

Features

  • Add v2 feature flags with weighted A/B test variants
  • Fix welcome page A/B test to include local-agent-mode clients

Release Tooling

  • Release script now handles existing tags gracefully

Don't miss a new DesktopCommanderMCP release

NewReleases is sending notifications on new releases.