# Reported issues for schwab-mcp

Pod holds 21 of 57 problems reported by people outside the maintainer team. Issues filed by the project's own owners, members and collaborators are excluded entirely — a maintainer's release checklist is not a warning to a prospective user.

Back to [schwab-mcp](/mcp/schwab-mcp).

## Most discussed

### Dependency CVE sweep: 55 advisories across 11 packages

osv-scanner found **55** known advisories across **11** dependencies of `schwab-mcp`.

Fix by upgrading each affected package to a patched version (follow each advisory for the fixed range). If a bump belongs in the SDK, Porter routes it upstream.

| package | advisory | summary |
|---|---|---|
| `click` `8.3.1` | [PYSEC-2026-2132](https://osv.dev/vulnerability/PYSEC-2026-2132) | Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allo

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/159) · 2026-08-16 · closed · outside contributor · 3 comments

### CVE: urllib3 2.6.3 — GHSA-qccp-gfcp-xxvc

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `urllib3` `2.6.3` (PyPI)
- **Advisory:** GHSA-qccp-gfcp-xxvc — https://osv.dev/vulnerability/GHSA-qccp-gfcp-xxvc
- **Summary:** urllib3: Sensitive headers forwarded across origins in proxied low-level redirects

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route i

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/156) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: urllib3 2.6.3 — GHSA-mf9v-mfxr-j63j

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `urllib3` `2.6.3` (PyPI)
- **Advisory:** GHSA-mf9v-mfxr-j63j — https://osv.dev/vulnerability/GHSA-mf9v-mfxr-j63j
- **Summary:** urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route it ups

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/155) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: pyjwt 2.11.0 — GHSA-w7vc-732c-9m39

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `pyjwt` `2.11.0` (PyPI)
- **Advisory:** GHSA-w7vc-732c-9m39 — https://osv.dev/vulnerability/GHSA-w7vc-732c-9m39
- **Summary:** PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in 

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/131) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: pyjwt 2.11.0 — GHSA-jq35-7prp-9v3f

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `pyjwt` `2.11.0` (PyPI)
- **Advisory:** GHSA-jq35-7prp-9v3f — https://osv.dev/vulnerability/GHSA-jq35-7prp-9v3f
- **Summary:** PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route it

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/130) · 2026-08-16 · closed · outside contributor · 1 comment

### Permission to add MCP Queen operational badge for io.github.lonniev/schwab-mcp

Hi — MCP Queen’s current public probe for **io.github.lonniev/schwab-mcp** reports an operational **A (91/100)** with **62 discovered tools**: https://mcpqueen.com/s/io.github.lonniev/schwab-mcp

We are asking before making any repository change. If you would like the live badge in your README, reply **PR welcome** and we will submit a one-line pull request near the top of your README. We will not open a PR without explicit permission.

Proposed line:

`[![MCP Queen operational grade](https://mc

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/98) · 2026-08-06 · closed · external user · 2 comments

### Deploy did not land: serving 262dbf8f, expected b918498d

Horizon has not served the merged commit after ~12 min.

- Expected (merged) sha: `b918498daa9489297b5fe28237c99c4cd08145c2`
- Observed deployed sha: `262dbf8f8df067b25f03340c7bce81fc61a30e3e`
- Observed version: `0.12.2`
- Service: https://schwab-mcp.fastmcp.app/mcp

This is the stale-wheel class (Horizon serving cached bytes) or a failed rebuild. A
touch-commit + redeploy usually clears a stale wheel; confirm the true live cause with a
fresh stateless `*_service_status` probe before changing c

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/90) · 2026-07-31 · closed · outside contributor · 2 comments

### Deploy did not land: serving 6eb4d61e, expected e2ac6099

Horizon has not served the merged commit after ~12 min.

- Expected (merged) sha: `e2ac60997c7b6c353d83afd190c6083ed6ca43dd`
- Observed deployed sha: `6eb4d61e96c230c01908c42e7969dbd15b414b3a`
- Observed version: `0.12.1`
- Service: https://schwab-mcp.fastmcp.app/mcp

This is the stale-wheel class (Horizon serving cached bytes) or a failed rebuild. A
touch-commit + redeploy usually clears a stale wheel; confirm the true live cause with a
fresh stateless `*_service_status` probe before changing c

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/62) · 2026-07-15 · closed · outside contributor · 1 comment

## Most recent

### CVE: urllib3 2.6.3 — PYSEC-2026-142

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `urllib3` `2.6.3` (PyPI)
- **Advisory:** PYSEC-2026-142 — https://osv.dev/vulnerability/PYSEC-2026-142
- **Summary:** urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPRes

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/158) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: urllib3 2.6.3 — PYSEC-2026-141

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `urllib3` `2.6.3` (PyPI)
- **Advisory:** PYSEC-2026-141 — https://osv.dev/vulnerability/PYSEC-2026-141
- **Summary:** urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., 

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/157) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — PYSEC-2026-3389

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** PYSEC-2026-3389 — https://osv.dev/vulnerability/PYSEC-2026-3389
- **Summary:** tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route it up

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/154) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — PYSEC-2026-3388

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** PYSEC-2026-3388 — https://osv.dev/vulnerability/PYSEC-2026-3388
- **Summary:** Tornado has out-of-bounds memory access via C extension

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route it upstream.

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/153) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — PYSEC-2026-3387

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** PYSEC-2026-3387 — https://osv.dev/vulnerability/PYSEC-2026-3387
- **Summary:** Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will rou

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/152) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — PYSEC-2026-2287

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** PYSEC-2026-2287 — https://osv.dev/vulnerability/PYSEC-2026-2287
- **Summary:** In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characte

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/151) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — PYSEC-2026-140

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** PYSEC-2026-140 — https://osv.dev/vulnerability/PYSEC-2026-140
- **Summary:** Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the ma

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/150) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — GHSA-pw6j-qg29-8w7f

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** GHSA-pw6j-qg29-8w7f — https://osv.dev/vulnerability/GHSA-pw6j-qg29-8w7f
- **Summary:** Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route it upstre

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/148) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — GHSA-mgf9-4vpg-hj56

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** GHSA-mgf9-4vpg-hj56 — https://osv.dev/vulnerability/GHSA-mgf9-4vpg-hj56
- **Summary:** tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will rou

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/147) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — GHSA-fqwm-6jpj-5wxc

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** GHSA-fqwm-6jpj-5wxc — https://osv.dev/vulnerability/GHSA-fqwm-6jpj-5wxc
- **Summary:** Tornado has cookie attribute injection via .RequestHandler.set_cookie

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route it upstream.

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/146) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — GHSA-cx3h-4qpv-8hc9

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** GHSA-cx3h-4qpv-8hc9 — https://osv.dev/vulnerability/GHSA-cx3h-4qpv-8hc9
- **Summary:** Tornado has out-of-bounds memory access via C extension

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route it upstream.

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/145) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — GHSA-78cv-mqj4-43f7

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** GHSA-78cv-mqj4-43f7 — https://osv.dev/vulnerability/GHSA-78cv-mqj4-43f7
- **Summary:** Tornado has incomplete validation of cookie attributes

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter will route it upstream.

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/144) · 2026-08-16 · closed · outside contributor · 1 comment

### CVE: tornado 6.5.4 — GHSA-3x9g-8vmp-wqvf

osv-scanner found a known vulnerability in a dependency of `schwab-mcp`.

- **Package:** `tornado` `6.5.4` (PyPI)
- **Advisory:** GHSA-3x9g-8vmp-wqvf — https://osv.dev/vulnerability/GHSA-3x9g-8vmp-wqvf
- **Summary:** Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the
dependency to a patched version (see the advisory for the fixed range); if the
bump lives in the SDK, Porter 

[Read the thread](https://github.com/lonniev/schwab-mcp/issues/143) · 2026-08-16 · closed · outside contributor · 1 comment

The remaining reports are on [the project's issue tracker](https://github.com/lonniev/schwab-mcp/issues).
