github akpw/mktxp v2.1.0
MKTXP v2.1.0

6 hours ago

🛡️ Security Advisory

Multi-Target /probe SSRF & Credential Disclosure (GHSA-cfw7-gh49-2vfp):

  • Restricted Target Overrides on Static Modules: static router entries (module_only = False) strictly reject dynamic target overrides with 403 Forbidden. The target parameter is only permitted if it matches the router's own configured hostname or IP.

  • Behavioral Change Note: in previous versions, querying /probe?module=<static_router>&target=<foreign_ip> would reuse the static router's credentials to connect to foreign_ip. Static entries no longer accept target overrides.

  • Enforced Target Allowlists for Dynamic Modules: dynamic probe modules (module_only = True) now enforce probe_allowed_targets by default against configured CIDR ranges, IP addresses, domain wildcards (*.corp.local), or *. Unlisted targets are denied with 403 Forbidden.

  • Global Probe Toggle: added enable_probe toggle in _mktxp.conf under [MKTXP] to enable or disable the /probe endpoint globally.

  • Special thanks to @tdabasinskas for identifying, responsibly disclosing, and verifying the remediation.

  • Breaking change 🔥: If you rely on dynamic multi-target probing, configure dedicated dynamic templates with module_only = True and configure probe_allowed_targets.

✨ New Features

Address List Counts without Individual Entries

  • newaddress_list_entries and ipv6_address_list_entries configuration options (default: True). Allows collecting total address list counts (total_address_list_counts = True) while suppressing individual entry metrics to prevent Prometheus cardinality explosions on large blocklists, #334

Batch Router RSC Exports & Custom SSH Settings

  • mktxp rsc: added support for batch exports across all configured routers (--all)
  • configurable SSH options: added per-router or default rsc_ssh_port and rsc_ssh_user settings for live SSH configuration exports
  • relative secrets path: added automatic resolution of relative credentials_file (secrets.yml) paths relative to the active configuration directory (--cfg-dir)

🚀 Improvements

  • Wireless Client Metrics Cardinality Optimization: exported wireless client uptime and TX/RX rates as numeric Prometheus gauges, reducing metric churn and label cardinality, #332
  • CLI Options: standardized --cfg-dir global option across all CLI subcommands (show, export, edit, diag, rsc)

⚙️ New System Configuration Options (_mktxp.conf)

[MKTXP]
    enable_probe = True                       # Enables the /probe multi-target scraping endpoint
    probe_allowed_targets = None              # Global allowlist of probe targets (CIDRs, IPs, hostnames, or '*' for all)

⚙️ New Device Configuration Options (mktxp.conf)

[default]
    probe_allowed_targets = None    # Allowed probe targets for dynamic modules: CIDRs, IPs, hostnames (e.g. 192.168.88.0/24, *.corp.local, or * for all)
    address_list_entries = True     # Emit individual address list entry metrics (set False if large lists cause high cardinality / only counts are needed)
    ipv6_address_list_entries = True # Emit individual address list entry metrics (set False if large lists cause high cardinality / only counts are needed)
    rsc_ssh_port = None             # Custom SSH port for live RSC exports (defaults to port in [RSC] or 22)
    rsc_ssh_user = None             # Custom SSH user for live RSC exports

Don't miss a new mktxp release

NewReleases is sending notifications on new releases.