Skip to content

Conversation

@cclauss
Copy link
Contributor

@cclauss cclauss commented Oct 22, 2025

Fix GHSA-j5gw-2vrg-8fgx

Via https://github.com/astral-sh/uv/releases v0.9.5

Motivation and Context

CVE-2025-62518 is a high-severity vulnerability.

How Has This Been Tested?

GitHub Actions tests.

Breaking Changes

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

@cclauss cclauss changed the title uv: Fix CVE-2025-62518 astral-tokio-tar issue GHSA-j5gw-2vrg-8fgx fix: uv CVE-2025-62518 astral-tokio-tar issue GHSA-j5gw-2vrg-8fgx Oct 22, 2025
@Kludex Kludex merged commit 35a9ccd into modelcontextprotocol:main Oct 22, 2025
18 checks passed
@cclauss cclauss deleted the uv-Fix-astral-tokio-tar-issue-GHSA-j5gw-2vrg-8fgx branch October 22, 2025 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants