This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 4d
MCP Browser & Automation
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
ai-agents
anti-detection
automation
browser-automation
cdp
chrome-devtools-protocol
+4 more
mcp
stealth-browser
typescript
web-scraping
Affected surfaces
auth
Summary
AI summaryUpdates Meta, 100.64/10, and CI across a mixed release.
Full changelog
Stealth, security, and MCP hardening since v0.3.0.
Features
- MCP: expose 6 previously-missing tools + return
isErrorresults on tool failures (#6)
Fixes
- CDP: fix three session-routing bugs across
useFrame()(#8) - page: well-formed
type()/press()key events;fill()clears the field first (#7) - security: private-network guard now also blocks CGNAT/tailnet (100.64/10), IPv6 ULA, and IPv4-mapped addresses (#5)
- transport: robustness — CDP command timeout, stderr leak fix, allow-origins handling (#4)
- stealth: remove the always-on
window.__veildetection tell (#2)
Meta
- CI: auto-publish to npm on version tag (#9)
- docs: README badges + corrected stealth-patch description (#1, #3)
Full install: bun add @achamm/veilbrowser / npm install @achamm/veilbrowser
Security Fixes
- Stealth: removed always‑on `window.__veil` detection tell (#2)
- Security: private‑network guard now blocks CGNAT/tailnet (100.64/10), IPv6 ULA, and IPv4‑mapped addresses (#5)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Veil
All releases →Related context
Beta — feedback welcome: [email protected]