Skip to content

CoinForge Studio 1.5.1 — security hardening

Choose a tag to compare

@hratchyan hratchyan released this 11 Jul 07:04

Security hardening for the AI Assistant and the hosted app. Recommended update if you use the AI Assistant.

Hardening

  • AI Assistant server: rejects non-loopback Host headers (blocks DNS-rebinding), compares its access token in constant time, and re-validates the export path so a design name can never write outside the exports folder.
  • Hosted app & site: added standard security response headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, HSTS, Permissions-Policy).
  • Account links: desktop-link records now self-expire so nothing lingers server-side.

No functional changes — same designer, same tools. See v1.5.0 notes for the AI Assistant itself.

Downloads

  • CoinForgeStudio-Portable.exe - no install, no account, fully offline.
  • CoinForgeStudio-Setup.exe - installer with shortcuts.

Windows SmartScreen: unsigned exe - More info -> Run anyway on first launch.