MacDub 0.3.1
Security fixes (MCP server)
Update if you use MacDub's MCP server, especially its HTTP transport.
- DNS rebinding: the HTTP transport accepted any origin containing
localhost(http://localhost.evil.com). Host and Origin must now name this machine exactly. - Path traversal:
delete_session,get_sessionandexport_sessionused the session id as a path, so an id like../../Claude/claude_desktop_configcould delete another app's settings. Ids must now be session ids. get_audio_snippetdeleted whateverpathnamed before writing; it now writes.wavfiles only and needsoverwrite: trueto replace one.- A negative
Content-Lengthcrashed the HTTP server; requests are now bounded (4 MB). - Add to Claude Desktop no longer overwrites a config it can't parse (it used to drop your other servers), and keeps a backup.
Fixes
- SpeechAnalyzer: a sentence it holds back (it sometimes merges two) is spoken after at most ~10–12 s instead of up to 20 s — benchmark update.
- Summaries with Claude Code or Codex: no more hang with long CLI output, and a CLI that exits early (not logged in) can no longer crash MacDub.
- Stopping while dubbing is still starting no longer leaves capture running.
- A data race between audio capture and the SpeechAnalyzer → SFSpeechRecognizer fallback.
Accessibility
VoiceOver now announces the sidebar, Start/Stop, Settings, every icon button and the controls of the Dubbing, Subtitles and AI & MCP screens by name (they were announced as "button").
Install
MacDub-0.3.1.dmg, or brew upgrade --cask macdub. Not notarized yet: right-click › Open the first time.