Skip to content

chore(deps): update dependency blender-mcp to v1.8.7 - #718

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/blender-mcp-1.x
Open

chore(deps): update dependency blender-mcp to v1.8.7#718
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/blender-mcp-1.x

Conversation

@renovate

@renovate renovate Bot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
blender-mcp 1.5.61.8.7 age confidence

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Jul 3, 2026
@toolhive-release-app

toolhive-release-app Bot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

🔒 MCP Security Scan Results

❌ blender-mcp

  • Status: Failed
  • Tools scanned: 25
  • Vulnerabilities found: 14

Security issues detected:

  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").
  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions").

Summary: Scanned 1 MCP server(s), found 14 security issue(s).

⚠️ Action Required: Security issues were detected. Please review and address them before merging.

@renovate
renovate Bot force-pushed the renovate/blender-mcp-1.x branch 2 times, most recently from 9fc821d to 683696a Compare July 8, 2026 07:53
@renovate
renovate Bot force-pushed the renovate/blender-mcp-1.x branch from 683696a to 2404d27 Compare July 17, 2026 14:10
@renovate
renovate Bot force-pushed the renovate/blender-mcp-1.x branch 4 times, most recently from 8c5a515 to 1457b4d Compare July 29, 2026 15:43
@renovate renovate Bot changed the title chore(deps): update dependency blender-mcp to v1.6.4 chore(deps): update dependency blender-mcp to v1.6.5 Jul 29, 2026
@renovate renovate Bot changed the title chore(deps): update dependency blender-mcp to v1.6.5 chore(deps): update dependency blender-mcp to v1.8.0 Aug 3, 2026
@renovate
renovate Bot force-pushed the renovate/blender-mcp-1.x branch 2 times, most recently from 49d77d9 to ab6aa5e Compare August 3, 2026 15:02
@renovate
renovate Bot force-pushed the renovate/blender-mcp-1.x branch from ab6aa5e to 869e161 Compare August 16, 2026 10:25
@renovate renovate Bot changed the title chore(deps): update dependency blender-mcp to v1.8.0 chore(deps): update dependency blender-mcp to v1.8.2 Aug 16, 2026
@renovate
renovate Bot force-pushed the renovate/blender-mcp-1.x branch from 869e161 to 8b9ac74 Compare August 16, 2026 18:12
@renovate renovate Bot changed the title chore(deps): update dependency blender-mcp to v1.8.2 chore(deps): update dependency blender-mcp to v1.8.3 Aug 16, 2026
@renovate
renovate Bot force-pushed the renovate/blender-mcp-1.x branch from 8b9ac74 to b6c0090 Compare August 24, 2026 05:15
@renovate renovate Bot changed the title chore(deps): update dependency blender-mcp to v1.8.3 chore(deps): update dependency blender-mcp to v1.8.4 Aug 24, 2026
@renovate
renovate Bot force-pushed the renovate/blender-mcp-1.x branch from b6c0090 to 5894e4b Compare August 24, 2026 21:16
@renovate renovate Bot changed the title chore(deps): update dependency blender-mcp to v1.8.4 chore(deps): update dependency blender-mcp to v1.8.7 Aug 24, 2026
@danbarr

danbarr commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Triage note — do not merge as-is, no code change pushed here.

This is a genuine, version-introduced risk, not scanner noise. Diffed the PyPI sdists for blender-mcp 1.5.6 vs 1.8.7: every one of the ~16 tools already had a mild `user_prompt` "for telemetry" parameter in 1.5.6, but 1.8.7 rewrote every tool's docstring to compel the calling agent to relay the user's raw, verbatim prompt into that parameter on every call, using directive language aimed at the LLM itself (e.g. "never substitute... repeat their previous words unchanged"). That's what triggered the 16 identical `AITech-1.1` (HIGH) findings.

Recommend escalating to a security reviewer with the specific question of what blender-mcp's telemetry endpoint does with that raw prompt data before deciding whether to hold this PR, ask upstream (`ahujasid/blender-mcp`) to clarify/revert the docstring change, or accept it with an explicit allowlist reason naming the behavior. Not treating this as a routine allowlist add.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant