Appsmith
Open-source low-code platform for building custom internal applications.
Appsmith ships an embedded MCP server, letting AI clients build and edit apps via structured tool calls
◆Recent moves
- 2d ago
Release v2.4.2 🌈
Patch release addressing Bouncy Castle and other dependency CVEs, a server memory issue in page cloning, and minor UI fixes. The Appsmith AI EOL reminder (September 30) is a repeat notice from v2.4, not new information. Routine security maintenance ahead of the EOL cutover.
View source ↗ - 9d ago
Release v2.4.1 🌈
Security-focused patch: Databricks URL validation closes an SSRF vector in JDBC connections, CVE-2026-75595 in netty-handler is patched, and UQI filter column names are validated to prevent SQL injection. The hardened WebClient builder lands on AI and Google Sheets plugins. Non-interactive appsmithctl restore adds an automation path for operators.
View source ↗ - 16d ago
Appsmith 2.4: embedded MCP server (beta) for AI-driven app building
⚡ SPARKAppsmith 2.4 ships an opt-in embedded MCP server (beta) that lets AI clients build and edit applications through tool calls, gated by the caller's own user permissions. Simultaneously, Appsmith's own AI datasource reaches end of life — the product is trading its proprietary AI layer for open MCP compatibility.
View source ↗ - 1mo ago
Release v2.3 🌈
v2.3 is primarily a large security hardening sprint — over 15 CVEs and GHSA patches including a path traversal fix in Git imports, multiple datasource authorization bypasses, and an XSS fix in SQL autocomplete. The functional additions (Ask AI for Community Edition, AI Copilot for Custom Widgets, new Card widget) expand the AI authoring surface that v2.4's MCP server will build on.
View source ↗ - 2mo ago
Release v2.2 🌈
v2.2 ships a long-requested feature: copying APIs, queries, and JavaScript objects across applications. Security batch addresses 17 vulnerabilities identified in release image scans, including blocking Redis datasource connections to the internal Appsmith Redis instance (GHSA-qhfj-g87x-m39w) — a critical internal SSRF path.
View source ↗ - 4mo ago
Release v2.1 🌈
v2.1 hardens the attack surface: comprehensive non-routable IP filter on WebClient closes multiple SSRF paths (GHSA-v49v-673j-g4vj, GHSA-m23h-pvf3-2m7p), Caddy admin interface locked to local socket, and Supervisord admin port removed. These are the hardening moves visible in v2.1–v2.3 that precede opening the MCP server in v2.4.
View source ↗