Skip to content

v0.7.2

Latest

Choose a tag to compare

@snapspecter snapspecter released this 28 Sep 00:46
Immutable release. Only release title and notes can be modified.
19e4529

Acknowledgements & Credits

  • Special thanks to @KulFilip for reporting the unvalidated dump_file path issue in the start_proxy tool.

What's Changed

Security Hardening & Bug Fixes

  • Dump File Path Confinement (start_proxy) (#30):

    • Added strict working directory boundary verification (_validate_contained_path) for dump_file in start_proxy.
    • Properly strips and preserves the append mode prefix (+) while resolving and validating target paths.
    • Rejects directory traversal (../), out-of-tree absolute paths, and symlink escapes.
    • Added comprehensive test suite covering dump file path security (tests/test_security_dump_file.py).
  • Scraper Code Generation Hardening (#29):

    • Replaced Python f-string interpolation with JSON-escaped string concatenation across all scraper templates (aiohttp, curl_cffi, playwright, requests) to prevent code execution via user-supplied URLs or headers.
    • Enforced a strict framework whitelist (SUPPORTED_FRAMEWORKS) to reject unsupported framework lookups.
  • Command Injection Prevention in cURL Generation (#29):

    • Quoted HTTP methods and URLs using shlex.quote in generated cURL commands to prevent shell metacharacter injection.
  • Scope Validation Hardening (#29):

    • Hardened domain matching in ScopeManager.is_allowed to require exact domain or proper dot-delimited subdomain matches, closing substring bypasses (e.g., example.com.evil.org).
  • Baseline Response Handling in Fuzzing (#29):

    • Refactored fuzz_endpoint baseline extraction to read status and content length directly from flow data, eliminating attribute errors when responses are absent.
  • Path Traversal Check Refactor (#26):

    • Replaced string-based prefix checks with Path.is_relative_to to prevent sibling directory bypasses (e.g., /app vs /app-evil).

Validation & Artifacts

  • All 46 automated unit and security tests passed.
  • Built wheel and source distributions:
    • mitmproxy_mcp-0.7.2-py3-none-any.whl
    • mitmproxy_mcp-0.7.2.tar.gz