github RunMaestro/Maestro v0.17.8
v0.17.8 | Security Release

latest release: v0.18.8-RC
2 hours ago

0.17.8 Highlights

🔒 This is a security release, and every user should install it. Maestro runs a small built-in server so maestro-cli and the phone interface can drive the app. Until now that server listened on your whole network from the moment Maestro opened, even with Live off, and it answered requests from any web page. Anyone who got hold of its URL (someone on the same Wi-Fi while you used the phone link, a pairing link that leaked, or a web page that knew the URL) could run commands on your computer through it.

📡 The server now stays on your computer until you turn Live on. While the button reads OFFLINE it listens on 127.0.0.1 only, so nothing on your network can reach it, and maestro-cli works exactly as before. Turning Live on opens it to your LAN for your phone, and turning Live off closes it again with a fresh token. If a Persistent Web Link let you reach Maestro from your phone with Live off, turn Live on to use it now.

🛡️ Web pages can no longer drive Maestro, even with the URL. The server refuses any browser request from a page it did not serve itself, WebSocket connections included, so a malicious site that learns your link gets nothing back. The file maestro-cli reads its token from is now readable by your user account only.

Also in 0.17.8

  • 🔁 Running Maestro behind a reverse proxy? Have it forward the original Host header (nginx: proxy_set_header Host $host;, Caddy does this already), or browser requests through it will be refused.
  • 🙏 Thank you to CopperKoi and YoAm, who found these problems and reported them responsibly. The full write-up is in advisory GHSA-q8p2-cpg2-fhpc.

Full Changelog: v0.17.7...v0.17.8

Don't miss a new Maestro release

NewReleases is sending notifications on new releases.