Security Fix
This release patches a path traversal vulnerability in the credential vault.
Fixed
- Credential ID validation - Added
validateCredentialId()method to prevent path traversal attacks inget(),delete(), andupdate()methods- Blocks path traversal characters (
..,/,\) - Enforces expected credential ID format:
cred_<timestamp>_<random> - Throws
CredentialSecurityErroron invalid input
- Blocks path traversal characters (
Upgrade
npm update @pansec/chrome-mcp-secureFull Changelog: v2.3.0...v2.3.1