v0.3.0
Latest
Sep 21, 2026
v0.3.0
Latest
Sep 21, 2026
Added
- •Wire format [V3] with authenticated metadata record
- •Stealth filename mode
- •Automatic hidden filename restoration upon decryption
- •Automatic conflict skip for duplicate files
- •Content Security Policy enforcement on desktop shell
- •Windows NTFS junction and mount point detection support
Changed
- •Full backward compatibility: V3 reader seamlessly decrypts V2 vaults
- •Expanded queue error display width for improved readability
- •Centralized OS file-locking and link validation across core engine
Fixed
- •CWE-22 / CWE-59 - Path traversal, cross-drive escape, and symlink redirection via sealed metadata and lock targets
- •CWE-200 / CWE-287 - Arbitrary UNC / network path acceptance enabling remote Windows NTLM credential exposure and SMB thread hangs
- •CWE-1021 / CWE-359 - Missing Content Security Policy in desktop WebView2 shell
- •CWE-451 / CWE-1007 - Unicode bidirectional override extension spoofing in restored filenames
- •CWE-178 / CWE-362 - Case-sensitivity mismatch between frontend deduplication and backend normalization causing frozen queue rows
- •CWE-835 / CWE-400 - Overwrite prompt infinite deadlock, window close lockout, and modal cancellation desync
- •CWE-362 / CWE-843 - Re-run queue event identifier collision causing state corruption of completed items
- •CWE-209 — Local filesystem path disclosure via unfiltered OSError exceptions in queue emission
- •CWE-372 / CWE-284 - Destination timestamp modification during overwrite pre-checks prior to authentication
Removed
- •Legacy CLI interface