github bytedance/UI-TARS-desktop v0.3.1

3 hours ago

This release closes several security issues in the Agent TARS CLI server (@agent-tars/cli, @tarko/agent-server). It changes how the server can be reached, so please read Upgrading from 0.3.0 before you update.

Upgrading from 0.3.0

If you run the CLI on your own machine and open it at http://localhost, nothing changes.

Otherwise:

  • The server only listens on 127.0.0.1 by default. It used to listen on all network interfaces. To reach it from another machine or from outside a container, pass --host, e.g. --host 0.0.0.0.
  • A non-loopback --host requires an access token. Set one with --auth-token or TARKO_AUTH_TOKEN (at least 16 characters). If you set none, a random token is generated on every start and printed with a ready-to-open ?token= link, so old links stop working after a restart. Set a fixed token if you need stable links.
  • Domains, reverse proxies and port forwarding need TARKO_ALLOWED_HOSTS. Requests whose Host header is not a loopback name, an IP address or the configured --host are rejected with 403 Invalid Host header. Add your hostname, comma-separated: TARKO_ALLOWED_HOSTS=agent.example.com.
  • A Web UI served from a non-localhost origin needs TARKO_ALLOWED_ORIGINS. Otherwise creating a session fails with 403 Origin not allowed. Use the full origin: TARKO_ALLOWED_ORIGINS=https://agent.example.com.
  • agentOptions from requests and URLs only accepts agentMode. This applies to /creating?agentOptions=..., welcome cards and POST /api/v1/sessions/create. Any other key (mcpServers, model, aioSandbox, ...) is rejected with 400. Configure those on the server instead.
  • Direct API calls need a CSRF token. Fetch one from GET /api/v1/csrf-token and send it as the x-csrf-token header on POST requests. When the server requires an access token, also send Authorization: Bearer <token>.

Example for a remote server behind a domain:

TARKO_AUTH_TOKEN=<a long random string> \
TARKO_ALLOWED_HOSTS=agent.example.com \
TARKO_ALLOWED_ORIGINS=https://agent.example.com \
agent-tars --host 0.0.0.0 --port 8888

See the CLI docs for details.

Security

  • Block request-body injection into agent constructor options; the server now binds to 127.0.0.1 by default (#1939)
  • Require an access token once the server leaves loopback (#2026)
  • Validate the Host header to prevent DNS rebinding (#1975)
  • Add CSRF protection, a CORS allowlist and security headers (#1853)
  • Stop HTML previews from escaping their iframe sandbox (#1938)

Bug Fixes

  • Answer a disallowed origin with 403 instead of 500 (#2044)
  • Repair unterminated strings in truncated tool call JSON (#1836)
  • Handle unknown model providers by defaulting to OpenAI-compatible (#1823)
  • Support streaming usage on LLM responses (#1737)

Features

  • Add embed-frame support for nav items (#1761)
  • Optimize the session status action design (#1766)
  • Set the remote browser viewport to the default viewport (#1748)
  • Add @gui-agent/cli, a CLI for GUI Agent automation (#1741)

Documentation

  • Document remote access settings for the agent server (#2043)

Full Changelog: v0.3.0...v0.3.1

Don't miss a new UI-TARS-desktop release

NewReleases is sending notifications on new releases.