Skip to content

kastelldev/kastell

v1.0.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

automation cli coolify devops digitalocean docker
+10 more
dokploy hetzner linode mcp security-audit self-hosted server-management typescript vps vultr

Affected surfaces

auth rce_ssrf

Summary

AI summary

Sanitize error cause chains to prevent API token leakage in all provider errors.

Full changelog

Security

  • Sanitize error cause chains to prevent API token leakage in all provider errors
  • Mask process title when --token flag is used
  • Replace execSync with spawnSync for ssh-keygen (prevent shell injection)
  • Add shell-safe assertions to domain FQDN and DNS check commands
  • Case-insensitive + nested security key detection in YAML config
  • Strip unknown fields from imported server data
  • Add IP address format validation to all SSH functions
  • Filter sensitive environment variables from child processes
  • Add StrictHostKeyChecking to interactive SSH connections
  • Set file permissions (0o600) on export files
  • Set directory permissions (0o700) on backup directories
  • Add Vultr and Linode to default provider validation
  • Clear error.config.data on Linode API failures (rootPass protection)

Security Fixes

  • Sanitize error cause chains — prevents API token leakage in all provider errors

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kastelldev/kastell

Get notified when new releases ship.

Sign up free

About kastelldev/kastell

Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.

All releases →

Beta — feedback welcome: [email protected]