Skip to content

kastelldev/kastell

v1.0.1 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

automation cli coolify devops digitalocean docker
+10 more
dokploy hetzner linode mcp security-audit self-hosted server-management typescript vps vultr

Affected surfaces

auth rce_ssrf

Summary

AI summary

Defense‑in‑depth fixes close SQL injection and path traversal vulnerabilities.

Full changelog

Added

  • quicklify snapshot create/list/delete — VPS snapshot management with cost estimates
  • Maintain integration: automatic snapshot offer before maintenance (with cost estimate)
  • sshKey.test.ts — dedicated tests for SSH key utilities (13 tests)
  • Provider snapshot support for Hetzner, DigitalOcean, Vultr, and Linode

Fixed

  • domain.ts: SQL escape for FQDN values (defense-in-depth against SQL injection)
  • restore.ts: Path traversal protection with basename() for --backup flag
  • yamlConfig.ts: Expanded security key detection (6 → 21 patterns including password, credential, jwt, bearer, etc.)

Security Fixes

  • domain.ts: SQL escape for FQDN values — defense‑in‑depth against SQL injection
  • restore.ts: Path traversal protection using basename() for the --backup flag

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kastelldev/kastell

Get notified when new releases ship.

Sign up free

About kastelldev/kastell

Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.

All releases →

Beta — feedback welcome: [email protected]