Fetching from the wire…
Public story · 2026-08-24 · high
Before v4.1.15, the setting only mattered if you'd separately approved each tool; updating widens unattended access for anyone who'd flipped it on.
Why now: Both fixes arrived in the same August 23 release, so updating for one pulls in the other whether you meant to or not.
Cline released version 4.1.15 on August 23, fixing a bug in its "Use MCP servers" toggle that had made the setting nearly pointless. Before this build, checking the box only mattered if you'd also approved each MCP tool individually, so most people who turned it on saw no change in behavior and assumed it did nothing.
Cline's v4.1.15 release notes say the toggle alone auto-approves every MCP tool call across every connected server in this version, with no per-tool opt-in required. Anyone who left the box checked because it seemed inert inherits a wider unattended tool surface after updating to v4.1.15.
MCP servers can reach file systems, shell commands, and third-party APIs, depending on what's connected. A setting that goes from mostly decorative to granting everything, with no security-specific callout, is easy to miss inside a general bug-fix release.
The same build fixed a second, unrelated issue. For custom OpenAI-compatible models, Cline had been inferring the model's capability list and stripping every tool from the request without saying so. Version 4.1.15's release notes list this alongside the MCP fix, giving a custom model integration that seemed to get worse over recent releases a documented explanation.
Neither bug was cosmetic. One made a permission toggle lie about what it approved. The other made a model lose tools it was supposed to have, with no error to explain why.
People running Cline with MCP servers connected should open the toggle's current setting and confirm what it's approving before leaving it running unattended.
Each link below shares sources, entities, or timing with this story.
OpenAI supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI supports MCP); both cover August, Cline, MCP, OpenAI; reported by the same outlet (github.com).
Claude Code uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover August, GitHub, MCP, OpenAI; reported by the same outlet (github.com).
Claude Code uses MCP / Shared entities / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Claude Code uses MCP); both cover August, GitHub, MCP, OpenAI; reported by the same outlet (github.com).
Cloudflare supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Cloudflare supports MCP); both cover August, MCP, OpenAI; reported by the same outlet (github.com).
MCP uses OAuth / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses OAuth); both cover August, MCP, Same; reported by the same outlet (github.com).
Toolport supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Toolport supports MCP); both cover August, MCP, Same; reported by the same outlet (github.com).
Claude Code uses MCP / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover Anyone, August, GitHub, MCP; reported by the same outlet (github.com).
Hexis supports MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Hexis supports MCP); both cover Anyone, August, GitHub, MCP; overlapping topics (anyone, august).