Skip to content

MacDub 0.3.1

Choose a tag to compare

@lordbasex lordbasex released this 23 Sep 07:44
· 25 commits to main since this release

Security fixes (MCP server)

Update if you use MacDub's MCP server, especially its HTTP transport.

  • DNS rebinding: the HTTP transport accepted any origin containing localhost (http://localhost.evil.com). Host and Origin must now name this machine exactly.
  • Path traversal: delete_session, get_session and export_session used the session id as a path, so an id like ../../Claude/claude_desktop_config could delete another app's settings. Ids must now be session ids.
  • get_audio_snippet deleted whatever path named before writing; it now writes .wav files only and needs overwrite: true to replace one.
  • A negative Content-Length crashed the HTTP server; requests are now bounded (4 MB).
  • Add to Claude Desktop no longer overwrites a config it can't parse (it used to drop your other servers), and keeps a backup.

Fixes

  • SpeechAnalyzer: a sentence it holds back (it sometimes merges two) is spoken after at most ~10–12 s instead of up to 20 s — benchmark update.
  • Summaries with Claude Code or Codex: no more hang with long CLI output, and a CLI that exits early (not logged in) can no longer crash MacDub.
  • Stopping while dubbing is still starting no longer leaves capture running.
  • A data race between audio capture and the SpeechAnalyzer → SFSpeechRecognizer fallback.

Accessibility

VoiceOver now announces the sidebar, Start/Stop, Settings, every icon button and the controls of the Dubbing, Subtitles and AI & MCP screens by name (they were announced as "button").

Install

MacDub-0.3.1.dmg, or brew upgrade --cask macdub. Not notarized yet: right-click › Open the first time.