Reported issues for schwab-mcp
Pod holds 21 of 57 problems reported by people outside the maintainer team. Issues filed by the project's own owners, members and collaborators are excluded entirely — a maintainer's release checklist is not a warning to a prospective user.
Back to schwab-mcp.
Most discussed
Dependency CVE sweep: 55 advisories across 11 packages
osv-scanner found 55 known advisories across 11 dependencies of schwab-mcp.
Fix by upgrading each affected package to a patched version (follow each advisory for the fixed range). If a bump belongs in the SDK, Porter routes it upstream.
| package | advisory | summary |
|---|---|---|
click 8.3.1 |
PYSEC-2026-2132 | Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allo |
Read the thread · 2026-08-16 · closed · outside contributor · 3 comments
CVE: urllib3 2.6.3 — GHSA-qccp-gfcp-xxvc
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
urllib32.6.3(PyPI) - Advisory: GHSA-qccp-gfcp-xxvc — https://osv.dev/vulnerability/GHSA-qccp-gfcp-xxvc
- Summary: urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route i
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: urllib3 2.6.3 — GHSA-mf9v-mfxr-j63j
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
urllib32.6.3(PyPI) - Advisory: GHSA-mf9v-mfxr-j63j — https://osv.dev/vulnerability/GHSA-mf9v-mfxr-j63j
- Summary: urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it ups
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: pyjwt 2.11.0 — GHSA-w7vc-732c-9m39
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
pyjwt2.11.0(PyPI) - Advisory: GHSA-w7vc-732c-9m39 — https://osv.dev/vulnerability/GHSA-w7vc-732c-9m39
- Summary: PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: pyjwt 2.11.0 — GHSA-jq35-7prp-9v3f
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
pyjwt2.11.0(PyPI) - Advisory: GHSA-jq35-7prp-9v3f — https://osv.dev/vulnerability/GHSA-jq35-7prp-9v3f
- Summary: PyJWT: Algorithm allow-list bypass when decoding with
PyJWK/PyJWKClientkeys
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
Permission to add MCP Queen operational badge for io.github.lonniev/schwab-mcp
Hi — MCP Queen’s current public probe for io.github.lonniev/schwab-mcp reports an operational A (91/100) with 62 discovered tools: https://mcpqueen.com/s/io.github.lonniev/schwab-mcp
We are asking before making any repository change. If you would like the live badge in your README, reply PR welcome and we will submit a one-line pull request near the top of your README. We will not open a PR without explicit permission.
Proposed line:
`[ sha:
b918498daa9489297b5fe28237c99c4cd08145c2 - Observed deployed sha:
262dbf8f8df067b25f03340c7bce81fc61a30e3e - Observed version:
0.12.2 - Service: https://schwab-mcp.fastmcp.app/mcp
This is the stale-wheel class (Horizon serving cached bytes) or a failed rebuild. A
touch-commit + redeploy usually clears a stale wheel; confirm the true live cause with a
fresh stateless *_service_status probe before changing c
Read the thread · 2026-07-31 · closed · outside contributor · 2 comments
Deploy did not land: serving 6eb4d61e, expected e2ac6099
Horizon has not served the merged commit after ~12 min.
- Expected (merged) sha:
e2ac60997c7b6c353d83afd190c6083ed6ca43dd - Observed deployed sha:
6eb4d61e96c230c01908c42e7969dbd15b414b3a - Observed version:
0.12.1 - Service: https://schwab-mcp.fastmcp.app/mcp
This is the stale-wheel class (Horizon serving cached bytes) or a failed rebuild. A
touch-commit + redeploy usually clears a stale wheel; confirm the true live cause with a
fresh stateless *_service_status probe before changing c
Read the thread · 2026-07-15 · closed · outside contributor · 1 comment
Most recent
CVE: urllib3 2.6.3 — PYSEC-2026-142
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
urllib32.6.3(PyPI) - Advisory: PYSEC-2026-142 — https://osv.dev/vulnerability/PYSEC-2026-142
- Summary: urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPRes
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: urllib3 2.6.3 — PYSEC-2026-141
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
urllib32.6.3(PyPI) - Advisory: PYSEC-2026-141 — https://osv.dev/vulnerability/PYSEC-2026-141
- Summary: urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(...,
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — PYSEC-2026-3389
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: PYSEC-2026-3389 — https://osv.dev/vulnerability/PYSEC-2026-3389
- Summary: tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it up
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — PYSEC-2026-3388
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: PYSEC-2026-3388 — https://osv.dev/vulnerability/PYSEC-2026-3388
- Summary: Tornado has out-of-bounds memory access via C extension
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstream.
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — PYSEC-2026-3387
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: PYSEC-2026-3387 — https://osv.dev/vulnerability/PYSEC-2026-3387
- Summary: Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will rou
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — PYSEC-2026-2287
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: PYSEC-2026-2287 — https://osv.dev/vulnerability/PYSEC-2026-2287
- Summary: In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characte
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — PYSEC-2026-140
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: PYSEC-2026-140 — https://osv.dev/vulnerability/PYSEC-2026-140
- Summary: Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the ma
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — GHSA-pw6j-qg29-8w7f
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: GHSA-pw6j-qg29-8w7f — https://osv.dev/vulnerability/GHSA-pw6j-qg29-8w7f
- Summary: Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstre
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — GHSA-mgf9-4vpg-hj56
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: GHSA-mgf9-4vpg-hj56 — https://osv.dev/vulnerability/GHSA-mgf9-4vpg-hj56
- Summary: tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will rou
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — GHSA-fqwm-6jpj-5wxc
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: GHSA-fqwm-6jpj-5wxc — https://osv.dev/vulnerability/GHSA-fqwm-6jpj-5wxc
- Summary: Tornado has cookie attribute injection via .RequestHandler.set_cookie
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstream.
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — GHSA-cx3h-4qpv-8hc9
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: GHSA-cx3h-4qpv-8hc9 — https://osv.dev/vulnerability/GHSA-cx3h-4qpv-8hc9
- Summary: Tornado has out-of-bounds memory access via C extension
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstream.
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — GHSA-78cv-mqj4-43f7
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: GHSA-78cv-mqj4-43f7 — https://osv.dev/vulnerability/GHSA-78cv-mqj4-43f7
- Summary: Tornado has incomplete validation of cookie attributes
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstream.
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
CVE: tornado 6.5.4 — GHSA-3x9g-8vmp-wqvf
osv-scanner found a known vulnerability in a dependency of schwab-mcp.
- Package:
tornado6.5.4(PyPI) - Advisory: GHSA-3x9g-8vmp-wqvf — https://osv.dev/vulnerability/GHSA-3x9g-8vmp-wqvf
- Summary: Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter
Read the thread · 2026-08-16 · closed · outside contributor · 1 comment
The remaining reports are on the project's issue tracker.