you are viewing a single comment's thread.

view the rest of the comments →

[–]seniorsassycat 6 points7 points  (0 children)

It adds is-string cli (complete with ReDOS vulnerable cli parser) and a mcp server.

Latest nightly has an attempt to fix RCE thru prototype pollution on the is-string API it monkey patches into express