Skip to content

Veil

v0.4.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai-agents anti-detection automation browser-automation cdp chrome-devtools-protocol
+4 more
mcp stealth-browser typescript web-scraping

Affected surfaces

auth

Summary

AI summary

Updates Meta, 100.64/10, and CI across a mixed release.

Full changelog

Stealth, security, and MCP hardening since v0.3.0.

Features

  • MCP: expose 6 previously-missing tools + return isError results on tool failures (#6)

Fixes

  • CDP: fix three session-routing bugs across useFrame() (#8)
  • page: well-formed type()/press() key events; fill() clears the field first (#7)
  • security: private-network guard now also blocks CGNAT/tailnet (100.64/10), IPv6 ULA, and IPv4-mapped addresses (#5)
  • transport: robustness — CDP command timeout, stderr leak fix, allow-origins handling (#4)
  • stealth: remove the always-on window.__veil detection tell (#2)

Meta

  • CI: auto-publish to npm on version tag (#9)
  • docs: README badges + corrected stealth-patch description (#1, #3)

Full install: bun add @achamm/veilbrowser / npm install @achamm/veilbrowser

Security Fixes

  • Stealth: removed always‑on `window.__veil` detection tell (#2)
  • Security: private‑network guard now blocks CGNAT/tailnet (100.64/10), IPv6 ULA, and IPv4‑mapped addresses (#5)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Veil

Get notified when new releases ship.

Sign up free

Beta — feedback welcome: [email protected]