WebFetch now blocks redirects that jump off the trusted docs path onto other pages.
What's wrong with this entry?
WebFetch now rejects a redirect that stays on the same host but moves off the documentation path that made the original URL trusted, closing a way for a trusted docs entry to be used to reach unrelated pages on that host.
- Matching covers the host as listed, the bare host and the
www.-prefixed form; hostname comparison still strips a leadingwww..
modelcontextprotocol.io
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.239
Data-loss-prevention blocks are marked separately from fetch failures
Both mention fetch
-
v2.1.236
Web fetch agent switch moved into per-host state
Both mention fetch