Skip to content

Mluva 1.2.1 — Security update

Choose a tag to compare

@1vecera 1vecera released this 21 Sep 14:14
741db42

Mluva 1.2.1 fixes the findings from the security audit and includes the identity, prompt editing and Live workspace improvements prepared for 1.2.0.

  • Native Codex rewrites run without tools, inherited global instructions or integrations. Mluva checks the session's capabilities before sending text and rejects unexpected tool activity. Existing Codex sign-in is preserved.
  • Incognito dictation, meeting and batch-preview audio use private memory-backed storage with crash cleanup and no disk fallback. Operating-system swap and crash dumps remain outside Mluva's control; the selected cloud speech provider still receives submitted audio.
  • ElevenLabs uploads reject redirects, preventing a redirect destination from receiving credentials or recordings.
  • Scratchpad, settings and personalization files are private before content is written and are replaced atomically. Application data directories are restricted to their owner.
  • The local Mermaid renderer uses patched DOMPurify 3.4.15 and lodash-es 4.18.1, with a reproducible locked build, checksum, component inventory and license notices.

Download mluva-1.2.1-source.tar.gz and SHA256SUMS below into the same directory, then run:

sha256sum --check SHA256SUMS
tar -xzf mluva-1.2.1-source.tar.gz
cd mluva-1.2.1
bash install.sh

Quit Mluva before upgrading. Setup preserves settings and saved conversations and installs the new Bubblewrap dependency. The matching Omarchy widget remains version 0.4.0. Native Codex isolation was verified with Codex 0.155.1; unsupported older protocols fail closed. See the installation guide.

The unpacked source archive passes 540 Linux tests, generated-feature checks, Ruff lint and formatting, and a real installation into a disposable prefix. Installed source files and renderer assets match the archive, and its data directory has owner-only permissions. The security changes also passed isolated native Codex, shortcut, conversation and Mermaid UI checks, ShellCheck, and a clean renderer rebuild with zero npm audit vulnerabilities.

This is a Linux source release. Omarchy is the primary platform; Fedora GNOME compatibility has not received recent live desktop acceptance. Tests used synthetic audio and local protocol providers; live microphone, real provider accounts and production Wayland interactions were not retested. Hosted product CI was not dispatched.

Changelog · Security fixes · Changes since the previous published release