Changelog
All notable, customer-facing changes to MisterShell are documented in this file.
The format is based on Keep a Changelog.
Versioning. MisterShell versions are
major.medium.minor. Read each release’s changes and upgrade notes before deployment. Within a major version, rolling upgrades are supported for clusters of at least three Cores unless a release requires a cold upgrade. Multi-Core cluster upgrades across major versions require a coordinated cold upgrade. Single-Core deployments update by replacing their container; cold/rolling classifications apply only to multi-Core deployments.Upgrade recovery. Back up the database before every upgrade and retain
DB_ENCRYPTION_KEY. Rollback requires restoring that backup and running the previous application version.Entries describe the features introduced in each release.
[2.0.18] - 2026-10-04
Added
- Browser shell sessions have a Copy all button beside Invite to copy current terminal text and retained scrollback without selecting it.
- Named keyboard-layout selection for Windows and Generic RDP resources, including Swiss French and Swiss German.
- Arista EOS support: SSH/SFTP sessions, configuration snapshots, health metrics, device facts and AI assistance.
- Per-sensor alert rate limits (default 600 per minute), with emitted and dropped alert counters.
Security
| Component | Update | Fixed CVEs |
|---|---|---|
| PyJWT (Core/Worker application and Azure CLI environments) | 2.15.1; the listed fixes were introduced in 2.14.0 | CVE-2026-102266, CVE-2026-102267, CVE-2026-102268, CVE-2026-102271, CVE-2026-102272, CVE-2026-102273 |
| urllib3 (Core/Worker application and Azure CLI environments) | 2.8.0 | CVE-2026-97687, CVE-2026-97689 |
| setuptools (Core/Worker Azure CLI bundle) | 83.0.0; the fix was introduced in 78.1.1 | CVE-2025-47273 |
| Ubuntu OpenSSL (Core, Worker, Sensor and Proxy) | 3.0.13-0ubuntu3.16, including the matching libssl3t64 package | CVE-2026-84782 |
| NATS: Go cryptography dependency | Updated to x/crypto 0.57.0 | CVE-2026-56855, CVE-2026-78662 |
Upgrade notes
- Cold upgrade required for multi-Core deployments: stop all Cores before starting the upgraded version. Single-Core deployments use normal container replacement.
[2.0.17] - 2026-09-27
Fixed
- Home content, quick-access cards, dashboard tabs, and trend choices respect the connected user’s permissions. Quick-access cards stay on one row.
- Dashboard location filters populate correctly. Map counts and popups follow the selected filters while retaining warnings for resources without coordinates.
- Health trend queries avoid repeatedly extracting large snapshot payloads.
- Unstable-resource evidence shows every transition for the selected resource over the ranking’s exact window, with pagination and permission checks.
- Health resource rows and summary counts use current health consistently; historical metrics remain available when expanded. Healthy rows use a green background, and a status filter matches the Map tab’s choices.
- Trend evidence remains scrollable when its contents exceed the page height.
[2.0.16] - 2026-09-26
Added
-
Fortinet FortiGate resources through RDK 2.0.7, with SSH sessions, operational commands, health metrics, configuration snapshots, and facts.
-
Administrators can limit the lifetime of newly generated API keys and registered SSH public keys. Account Security enforces these limits alongside the backend; existing key expirations remain unchanged.
-
Connect-time credential prompts let users save a missing personal credential after successful authentication or correct an existing saved credential after authentication rejection. Web sessions are excluded from this flow.
-
Human sign-ins have a configurable maximum duration: 12 hours by default,
0for unlimited. A warning appears five minutes before sign-out, followed after dismissal by a seconds countdown in the top navigation. Active work does not extend the deadline; users sign in again and reconnect at expiry.
Upgrade notes
- Cold upgrade required: close existing client connections and upgrade all Cores/brokers together. Existing human sign-ins must reconnect. Bounded SSO requires users to authenticate again at an identity provider that supports forced authentication and provides a fresh authentication time. Back up the database before upgrading; stop all Cores/brokers before starting the updated version.
Changed
-
Resource and credential forms distinguish service account credentials used for snapshots from personal credentials required for interactive sessions.
-
Resource browser status icons update without reloading the tree. Narrow panels hide resource type labels when they would overlap the status icons.
-
Account Security labels personal SSH keys explicitly as SSH public keys.
-
Confirmation dialogs share one layout, wording and behaviour across the application: a severity icon, the item’s name in bold, consequences on a single line, and the action named on the confirm button. They ignore clicks outside the dialog and cannot be closed while the action is running; a failed action keeps the dialog open so it can be retried.
-
Discarding unsaved changes — leaving a note draft, closing a config template editor, or switching shell profile — now asks for confirmation in the application’s own dialog instead of the browser’s.
-
Resetting a user’s password shows the new one-time password in its own dialog after the reset is confirmed.
[2.0.15] - 2026-09-24
Changed
- SSH gateway: sign in with your own SSH key. Register public keys under Account Security → My SSH keys; on the Text UI the key replaces your password and any required verification code or browser sign-in still follows. On resources that allow personal SSH keys, direct connections sign in with the key alone.
Fixed
- SSH gateway: when the gateway stops or restarts while you are in the Text UI, your terminal is now restored (mouse reporting and full-screen mode switched off) instead of filling with escape sequences.
- Account Security, Personal Information and Personal Vault pages scroll when their content is taller than the window.
Removed
- Personal API keys no longer sign in over SSH. The resource option Allow personal API key for native SSH automation is replaced by Allow personal SSH keys for native SSH automation; existing opt-ins are not carried over.
Upgrade notes
- Multi-Core deployments require a coordinated cold upgrade for this release.
[2.0.14] - 2026-09-22
Added
- SSH gateway: use your own SSH client with account authentication or browser sign-in. Connect directly to a resource for interactive work or automation; personal API keys are accepted only on resources that explicitly allow them. Sessions retain the same access controls, approvals, policies, and recording.
- Text UI: browse resources, open independent shell tabs, read summaries and Notes, and use AI Session Assist from your terminal. Includes keyboard and mouse navigation, resizable panes, clipboard selection, and light/dark themes.
- SFTP catalog access: upload and download location files with SFTP clients or modern SCP. Transfers between the catalog and resources use the browser’s governed file manager.
- Multiple shell sessions: open up to three sessions per user/resource by default, shared across browser and native SSH access. Administrators can adjust the limit; each browser connection opens in its own pin.
- AI analysis is available from ended shell-session entries and first configuration snapshots, subject to permissions and configured agents.
Changed
- Resource and location pages use a consistent tab order. Compliance, Alerts, and Syslog appear as Summary cards according to permissions and licensed features. Graphical-only resources open on Notes.
- Worker session capacity is one total limit across all connection types. Graphical sessions remain limited to one per user/resource.
- Access controls consistently follow granted actions and locations across navigation, administration, policy editors, resource evidence, and Review. Compliance, collected logs, and IDS alerts can be granted independently of policy viewing. Configuration previews and pushes require execute access.
- Resource readers can view collected facts and assigned tags. Event feeds show activity for accessible resources regardless of who initiated it.
- Facts tabs are marked beta. Missing values display as
-and export as empty CSV cells. - Updated backend and browser dependencies while preserving legacy RSA/SHA-1 SSH compatibility.
Fixed
- Failed authentication no longer adds empty snapshots or misleading fact-collection failures.
- Switching between pinned pages and tabs preserves live connections without navigation loops. Closing a connection pin confirms termination and leaves sibling sessions running.
- Resource creation and editing use consistent verification results. Tree icons and detail badges show only checks supported by the resource type.
- Snapshot progress follows the collection deadline instead of timing out early in the browser. The snapshot selector reflects the selected result and indicates when collection is running.
- Cisco SD-WAN collection and vBond identity detection use the appropriate device information.
Removed
- The resource Connect tab and More menu. Start connections from the location tree; evidence cards appear on Summary and supported tabs appear directly in the strip.
- AWS account-alias configuration and EC2 RAM-capacity collection. EC2 inventory remains available, with RAM capacity left empty.
Security
| Dependency | Update | Advisory references |
|---|---|---|
| AnyIO | 4.15.1; fixes TLS hostname validation and process-pool deadlocks | CVE-2026-63374, CVE-2026-64847 |
| Markdown editor | 6.5.6; fixes script injection through code-block language labels | CVE-2026-84992 |
Upgrade notes
- Multi-Core deployments require a coordinated cold upgrade: stop all old Cores before starting the new version. Single-Core deployments use normal container replacement. Back up the database first; rollback requires restoring that backup.
- Existing role grants are migrated while preserving location restrictions. Configuration preview-only access does not automatically grant push access.
- To enable native SSH access, ensure the SSH gateway is enabled and expose its
configured port (
2222by default).
[2.0.13] - 2026-09-16
Added
- Personal and team vault: save credentials, share them with selected roles, and view encrypted value history. Team members can edit, delete, or change sharing; sharing includes history, and making an entry personal gives the person making that change sole access.
- Generate vault passwords with configurable length and character requirements.
- Use compatible vault credentials or enter temporary values when opening sessions, browsing files, or transferring files. Connections use the latest saved vault value.
- Vault access and changes are audited without secrets. Deleting users preserves team entries; roles still used by team entries cannot be deleted.
Changed
- Personal Vault separates credential templates from personal/team entries and shows the age of each entry’s last update.
Fixed
- Notifications reconnect after signing out and back in without a page reload.
Upgrade notes
- Existing credential templates and personal fills are preserved. Back up the database before upgrading; rollback requires restoring that backup.
[2.0.12] - 2026-09-16
Added
- Authenticator MFA: Local and LDAP sign-in can require an authenticator app, email MFA, or neither. Enrollment includes one-time recovery codes.
- Manage authenticators and recovery codes in My Account; administrators can reset enrollment. The built-in recovery account remains password-only.
- Deleting a user or LDAP provider removes its MFA enrollment while retaining audit history. Changing MFA methods preserves enrollment for later reuse.
Changed
- My Account groups passwords, MFA, API keys, and sessions under Account Security. Personal credentials are renamed Personal Vault.
- The sign-in screen has light and dark photographic backgrounds.
Upgrade notes
- Multi-Core deployments require a coordinated cold upgrade. Existing email-MFA requirements are preserved; affected users must sign in again. Back up the database and stop all Cores before starting the updated version.
[2.0.11] - 2026-09-15
Changed
- More consistent light/dark themes, status colors, borders, and table headers.
- Review places session, agent, change, health, compliance, and approval timelines before reports and logs. Monitor’s Tools and Compliance views use simpler cards.
Fixed
- Single-Core startup applies platform updates reliably after quick restarts.
- Charts, documentation diagrams, and map markers follow theme changes correctly.
- Live terminals and replay follow shell profiles; replay retains recorded size and output.
- Location summaries align metrics and maps on wide screens and stack them on narrow screens.
Upgrade notes
- Multi-Core deployments upgrading from before 2.0.10 still require a coordinated cold upgrade. See the 2.0.10 upgrade notes.
[2.0.10] - 2026-09-14
Added
- Automation routing: Switch controls choose the first matching route, with AND/OR conditions, list comparisons, fallback/error paths, and replay details.
- Approval workflows: Approve controls pause playbooks for a role member’s decision, with templated messages, optional email, expiration, and separate approved, denied, and expired paths.
- Session and File Transfer policies can require approval, with configurable approvers, expiration, access duration, and self-approval. Approval comes before ordinary access checks and does not bypass them; each operation needs its own.
- A personal Approvals inbox for requests and decisions, accessible without Automate or Govern access. Review retains permission-scoped approval history even after the source changes or is deleted, subject to retention settings.
- Roles still needed by approval rules, unfinished runs, or requests are protected from deletion.
Changed
- Automation Studio adds custom labels, clearer connections, draggable route ordering, a resizable editor, and consistent source bindings.
- Policy editors separate selection criteria from actions. Approval details are consistent across the inbox and history.
Fixed
- Approval decisions reliably resume waiting playbooks.
- Automation nodes remain readable in dark mode; dialog buttons remain visible on narrow screens.
Upgrade notes
- Multi-Core deployments require a coordinated cold upgrade, including from 2.0.9. Old and new Cores must not run together.
- External PostgreSQL must be version 16 or newer. Take a complete database backup; rollback requires the previous application version and that backup.
[2.0.9] - 2026-09-13
Added
- A fleet Compliance timeline with filters and the definition and result saved for each evaluation. Resource and location History show the same evidence.
- Optional email MFA for Local and LDAP sign-in, enabled only after a successful test code. Local settings also cover password rules, reset-link lifetime, and email verification.
- Credential templates can prompt for temporary credentials for terminal, graphical, and file operations without saving them to the account.
Fixed
- The built-in recovery account remains password-only when email MFA is enabled.
- Accounts linked to external providers cannot sign in with a retained local password.
[2.0.8] - 2026-09-12
Added
- Optional CARTO light/dark map backgrounds through
carto_api_key; OpenStreetMap remains the default. - Fact assertions can check related facts with At least one, Every, None, and Count conditions. The editor offers fields from the selected definition, grouped fact types, and resource search for testing.
Changed
- Fact policies can pass or fail using available observations from partial collections. Compliance details show collapsible definitions, results, and matching evidence.
Fixed
- Compliance automation treats an error-to-pass transition as a resolution.
- MCP fact history resolves unambiguous keys and reports ambiguity; fact discovery honors the requested type. Command results support complete text pagination.
- Device command rejections and unavailable session evidence report clear failures.
- Location health includes unknown states; the unused
physical_port_summaryfield is removed. - Database restore checks that the Core API is suspended before replacing data.
- Policy selectors and file-rule visibility behave consistently.
Security
- Generated administrator passwords stay out of startup logs. Set
INITIAL_ADMIN_PASSWORDfor a new installation, or usemsh -y reset admin-userto display a recovery password once.
Upgrade notes
- Replace
YAMI_TLS_CERT_CNwithTLS_CERT_CN. Move custom certificate mounts from/etc/yami/tls/server.crtand/etc/yami/tls/server.keyto/etc/ssl/certs/mistershell.crtand/etc/ssl/private/mistershell.key.
[2.0.7] - 2026-09-10
Added
- A fleet Health timeline with filters, failing metrics, and metric history.
- Resource and location History include AI runs and active sessions.
Changed
- Resource verification supports consistent SSH identity checks and explicit host-key acceptance.
- Clearer fact status, ordering, references, and layouts. Location navigation removes the duplicate Resources tab and simplifies Locations Only mode.
Fixed
- Live feeds stay responsive under load and retain simultaneous updates.
- Scheduled jobs run independently without interfering with one another.
- Terminal sizing, Notes highlighting, and resource-browser overflow are improved.
Upgrade notes
- Existing valid SSH host-key pins are preserved or repaired. Resources without a usable fingerprint have strict checking disabled to restore connectivity; use Re-check and accept the key to restore strict checking. New resources still default to strict checking.
Security
Updated bundled dependencies to address the following advisories.
| Component | Security update | Advisory references |
|---|---|---|
| HTTPX2 / HTTPCore2 | 2.12.0 | CVE-2026-84378, CVE-2026-84379, CVE-2026-84380, CVE-2026-84381, CVE-2026-84382 |
Go SSH (golang.org/x/crypto) | Dependency update | CVE-2026-56854 |
| Apache Thrift | Dependency update | CVE-2026-43871 |
| gRPC-Go | Dependency update | CVE-2026-84304 |
| Vitest | Dependency update | CVE-2026-84373 |
js-yaml | Dependency update | CVE-2026-84375 |
postcss-selector-parser | Dependency update | CVE-2026-9358 |
@humanfs/node | Dependency update | GHSA-p498-v437-472g |
[2.0.6] - 2026-09-08
Added
- Fact views show collection status, freshness, nested values, and related facts.
- Governed file transfers: move files between compatible SSH resources and location catalogs, with permissions, transfer policies, progress, cancellation, and history.
- Credential usage lists linked resources and supports replacing their credentials.
- Network diagnostics share one catalog across Monitor, MCP, and Automation, with up to five selected Workers. MCP exposes Worker selection; without a selection, MCP and Automation use the first available Worker, searching from the root.
Changed
- Partial collections retain valid observations without withdrawing unseen facts; incomplete evidence produces a compliance error.
- Generic Worker-task creation requires unrestricted administrator access. Diagnostic inputs are redacted from audit records.
- Automation diagnostics target Workers instead of locations. Session sharing and CSV validation consistently apply the user’s location permissions.
Fixed
- File listings refresh after transfers, and interrupted connections recover more reliably.
- Sensors keep their working configuration when an update fails validation or cannot start.
Security
- Sensor configuration rejects values that could inject unintended settings.
Upgrade notes
- Multi-Core deployments require a coordinated cold upgrade. Update Core and Worker images together; older versions are incompatible with the new catalog. Back up the database and stop all Cores before starting the updated version.
- Checks using retired network fact types are deleted and affected policies are disabled. Review them before re-enabling. Facts and evaluation history remain readable; recovering deleted checks requires the complete pre-upgrade backup.
[2.0.5] - 2026-08-30
Added
- Full-text search in the documentation viewer, with ranked results and highlighted excerpts.
Changed
- AI command discovery follows the resource type’s read-only guardrails, including when settings are unavailable.
- AI fact queries require exact fact-type identifiers and list valid choices when an identifier is invalid.
Fixed
- Incomplete configuration captures are rejected instead of appearing as changes.
- Configuration history shows correct counts and pagination when filtered by date.
[2.0.4] - 2026-08-28
Changed
- Reports require Base or higher; log forwarding requires Pro or higher. The interface displays these requirements before use.
Fixed
- Location permissions apply consistently to notes, history, configuration changes, Quick Assist, and MCP tools, including resource inspection.
[2.0.3] - 2026-08-28
Fixed
- Location-scoped users can navigate ancestors of permitted branches without gaining access to other resources. Ancestor summaries include only permitted descendants; Notes identifies navigation-only locations.
- Role location selection preserves explicit choices and clearly distinguishes inherited access, including overlapping branches.
[2.0.2] - 2026-08-26
Added
- Built-in roles for common responsibilities, available to inspect and duplicate into editable roles. The Quick Start access-control step is removed.
Changed
- AI Chat and Quick Assist share one execute permission.
- Permissions consistently distinguish reading, editing, deleting, and executing.
Resource reads allow read commands; writes allow write commands; execution
covers tests, snapshots, and connections. Fact management uses
app.facts.write. - Worker, Sensor, and Proxy management uses
app.fabric.*permissions; evidence and policy permissions remain separate.
Fixed
- AI controls and account role badges accurately reflect granted permissions.
- Active sessions are no longer closed as idle; the four-hour safety limit remains.
Upgrade notes
- Multi-Core deployments require a coordinated cold upgrade. Back up the database and stop all Cores before starting the updated version.
- Existing AI grants migrate automatically. Terraform and direct API role
definitions must replace
app.ai.chatandapp.ai.quick_assistwithapp.ai.execute.
[2.0.1] - 2026-08-26
Added
- Resources without coordinates inherit their location’s map position, while respecting visibility of the source location.
Fixed
- Database backups and remote Worker commands work correctly in packaged installs.
- Reaching an AI step or token budget reports a warning with guidance, including for automation runs.
[2.0.0] - 2026-08-24
Breaking release: replacement licenses are required, and legacy Notes and attachments are deleted without conversion. Read the upgrade notes below before deploying. Multi-Core installations require a coordinated cold upgrade.
Added
- Edition licensing: Free supports 25 resources; Base adds custom commands, agents, prompts, skills, and purchased resource capacity; Pro adds remote Workers, SSO, and high availability; Enterprise adds policies, recording, automation, and configuration workflows. IDS, Log collector, and External proxies are separate extras requiring Base or higher.
- Preview license installation and removal, including capacity effects. Manage
licenses in the UI or with
msh license installandmsh license remove; the Licensing page shows edition, usage, expiry, and each license’s status. - OIDC and SAML providers can obtain groups from LDAP by email and apply their own role mappings. Directory failures or ambiguous matches deny sign-in.
- OIDC providers can enable delegated MCP access for external AI platforms on Pro. Users must have signed in previously; their permissions apply. Personal API keys remain supported.
- Authentication providers have stable, chosen URL mnemonics and show the URLs to register with the identity provider. Existing provider URLs are preserved.
- Console backup and recovery: create, list, and validate SFTP backups with
msh; restore eligible single-Core installations after archive validation. Multi-Core restore remains a manual PostgreSQL operation. - AI Audit: trace AI runs, model requests, and tool calls. Read access shows metadata; write access allows troubleshooting inputs and outputs. Retention defaults to seven days, with metadata-only forwarding available.
- SSH host-key verification also protects background checks, snapshots, and commands when strict checking and a pinned key are configured.
- Azure networking facts include virtual networks, subnets, interfaces, and routes.
Changed
- Resource onboarding tests connections before creation. CSV imports validate rows and allow retrying failures without repeating successful imports.
- Notes use Markdown with independent attachments: 10 MiB for images/PDFs and 1 MiB for UTF-8 text.
- Unavailable licensed actions show their requirements; inactive extra screens are hidden. Previously collected evidence remains readable with permission.
- Licensing errors give explicit refusals; confirmed entitlement remains valid for up to 24 hours during temporary failures. Exceeding capacity blocks new items while preserving access and deletion.
- Log collector capacity counts collecting Workers; administrators set throughput.
- SSH connections use consistent timeouts, with fleet defaults and per-resource overrides.
Removed
- Database-backup HTTP endpoints and
db_restore.sh. Use scheduled Database Backup tasks or themshbackup and restore commands. - The
notes_attachment_max_bytessetting, replaced by fixed attachment limits.
Fixed
- External AI clients can reach MCP through packaged installations.
- Older graphical recordings above the current live-session size limit remain replayable.
- SSO works behind HTTPS-terminating load balancers using the public application base URL.
- Deactivated accounts cannot sign in through external providers.
Upgrade notes
- Back up the database before upgrading. Multi-Core deployments require a coordinated cold upgrade: stop all Cores before starting the updated version. Obtain replacement licenses before upgrading. Set Licensing email to the purchase email and install replacements immediately afterward. Mismatched and older licenses grant no entitlement and are not converted.
- Until replacement licenses are installed, the installation runs as Free: external sign-in, new recordings, policy/automation work, remote Worker tasks, and custom-definition editing are unavailable. Local sign-in, existing sessions, and stored evidence remain available; nothing is deleted for exceeding capacity.
- Preserve needed Notes before upgrading: every legacy TipTap/DrawIO note version and attachment is deleted without conversion.
- Update direct API integrations: remove trailing slashes, use
PATCHfor partial edits,PUTfor assignments and ordering, andPOSTfor email verification and password generation. Tree and note-attachment creation returns201 Created. - Multi-Core deployments must disable explicitly enabled embedded Workers and run separate Workers. Leaving the embedded Worker setting unset disables it automatically for multi-Core use.
- Replace logs-per-second licenses with capacity for collecting Workers; there is no numeric conversion.
- Set
app_base_urlto the public URL before enabling OIDC or SAML providers.
Security
- MCP requests are rate-limited per authenticated user or, for unauthenticated requests, per source address. These allowances are separate from web access; an address over its public limit is blocked before authentication.
Updated frontend and build dependencies:
| Dependency | Advisory references |
|---|---|
brace-expansion | CVE-2026-14257, CVE-2026-69152, CVE-2026-13149 |
dompurify | GHSA-c2j3-45gr-mqc4, GHSA-55q2-fjhq-7xh7 |
fast-uri | CVE-2026-75931, CVE-2026-75975, CVE-2026-75899, CVE-2026-76172, CVE-2026-18446, CVE-2026-16221 |
immutable | CVE-2026-59879, CVE-2026-59880 |
js-yaml | CVE-2026-59869, GHSA-5p4m-2wfm-xmqj |
mermaid | CVE-2026-71438, CVE-2026-50159, CVE-2026-71437, CVE-2026-71436, CVE-2026-71439 |
nanoid | CVE-2026-67214, CVE-2026-67213 |
orval | CVE-2026-62680, CVE-2026-72716, CVE-2026-71866, CVE-2026-62681, CVE-2026-71864, CVE-2026-71869, CVE-2026-71871, CVE-2026-71867, CVE-2026-71868, CVE-2026-71865, CVE-2026-62682, CVE-2026-72717 |
postcss | CVE-2026-69153, CVE-2026-73646 |
quasar | CVE-2026-73647 |
Updated runtime and bundled-client dependencies:
| Component | Security update | Advisory references |
|---|---|---|
aiohttp | 3.14.3 | CVE-2026-69244 |
Application and Azure CLI: cryptography | 50.0.0 | CVE-2026-69247, CVE-2026-69249 |
kubectl: golang.org/x/text | 0.39.0 | CVE-2026-56852 |
usql: gRPC | 1.82.1 | GHSA-hrxh-6v49-42gf |
| MCP Python SDK | 1.28.1 | CVE-2026-52869, CVE-2026-52870, CVE-2026-59950 |
pyasn1 | 0.6.4; decoder denial-of-service fixes | CVE-2026-59884, CVE-2026-59885, CVE-2026-59886 |
[1.6.9] - 2026-07-17
Added
- SAML email/name attribute mapping with presets for Entra ID, ADFS, and Okta.
Fixed
- Sign-ins without supplied names or email addresses no longer break the user list.
- Email matching ignores capitalization, preventing sign-in failures and duplicate accounts during linking.
[1.6.8] - 2026-07-15
Added
- AI Session Assist can run custom Generic SSH read commands allowed by guardrails.
- SAML providers can sign authentication requests with a matching certificate and private key; the signing certificate is included in provider metadata.
Changed
- AI Guardrails restrict catalog commands to read mode for all agents, including background automation. Operators’ own commands are unaffected; administrators can disable guardrails per resource type.
- Identity provider settings reject unknown or misplaced fields. Disabling SAML request signing clears the saved signing keys.
Fixed
- Custom command parameter fields appear after creation, required values reach devices correctly, and invalid commands do not prevent other batch entries.
- Command templates preserve shell brackets, PowerShell casts, and literal text.
Parameters use
{name:type}; optional[ ]groups require all their parameters; a backslash escapes literal brackets, braces, or backslashes. Invalid types are rejected when saving. - Generic SSH resources show Actions and support custom commands.
- LDAP TLS verification trusts built-in authorities alongside custom CAs.
- Provider edits preserve mappings and masked secrets, apply valid changes, and report invalid settings clearly. SAML connection tests report the actual signing state and explain missing keys.
Upgrade notes
- Open and save previously created custom commands with missing parameter fields to regenerate those fields. API integrations must remove unknown provider fields that earlier versions silently ignored.
[1.6.7] - 2026-07-15
Fixed
- SAML setup derives and displays its entity ID and ACS URL from App Base URL. Set the public HTTPS URL before setup; update the identity provider if it changes.
- SAML Test Connection correctly validates configuration and certificates.
Removed
- The SAML request-signing option. Requests are unsigned in this release; requiring signed assertions remains enabled by default.
Security
| Component | Security update | Advisory references |
|---|---|---|
click | 8.4.2; editor-helper update | CVE-2026-7246 |
Click maintainers dispute the vulnerability classification. See the upstream release notes for the implementation change.
[1.6.6] - 2026-07-13
Added
- Reorder Config policies by dragging or using arrows; ordering affects display only.
Changed
- Policy tables share consistent layouts and editable toggles for notification, logging, suppression, forwarding, and discard options.
Fixed
- Tag-scoped Fact policies evaluate again after the next snapshot. Config policy tag matching is also more reliable.
[1.6.5] - 2026-07-13
Added
- CA Certificates: manage private certificate authorities for connections with
TLS verification, including identity providers, SMTP, AI models, webhooks, and
log forwarding. Containers also accept PEM certificates mounted at
/etc/certs. - Explicit LDAP and SMTP TLS verification controls, plus a per-Web-resource Ignore certificate errors option, off by default.
- Azure OpenAI, Google, and xAI model configuration, including Azure API version.
Fixed
- Invalid authentication, session, task, and compliance data produce clear errors. Task notifications, configured timeouts, and API-log retention honor settings.
Security
- SAML sign-in must start from MisterShell; unsolicited identity-provider-initiated sign-in is rejected.
Upgrade notes
- Existing LDAP and SMTP configurations remain unverified until TLS verification is enabled. Load private CAs before enabling it; new LDAP providers default to verification.
- API clients for
/api/v1/sessions/history,/api/v1/api-logs/, and/api/v1/app-logs/must read rows fromdataand pagination frommeta, replacing the formerdata.itemswrapper.
[1.6.4] - 2026-07-11
Security
Updated bundled clients to address the following advisories; supported database drivers are unchanged.
| Bundled client | Advisory references |
|---|---|
kubectl | CVE-2026-25681, CVE-2026-27136, CVE-2026-33814, CVE-2026-39821 |
usql: Go standard library | CVE-2026-27145, CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVE-2026-33810, CVE-2026-33811, CVE-2026-39820, CVE-2026-39836, CVE-2026-42499, CVE-2026-42504 |
usql: JSON parser | CVE-2026-32285 |
usql: JOSE | CVE-2026-34986 |
usql: SSH (golang.org/x/crypto) | CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597 |
usql: OpenTelemetry | CVE-2026-39883 |
usql: Apache Thrift | CVE-2026-41602 |
usql: Billy filesystem | CVE-2026-44973 |
[1.6.3] - 2026-07-11
Security
- Removed compilers and development headers from runtime images to reduce their attack surface.
[1.6.2] - 2026-07-11
Security
- LDAP rejects empty passwords, protects directory lookups from injection, and honors the configured TLS mode.
- SAML responses are tied to the initiating sign-in request to prevent replay.
Fixed
- Paginated lists retain accurate filtered totals beyond the last page and handle out-of-range pagination consistently.
- Rule-ordering errors clearly identify invalid rules. Empty collector-rule
reorder requests return validation status
422. - Health endpoints enforce rate limits and auditing; rate-limited and failed requests are included in the audit trail.
- Real-time activity, security events, and automation processing recover after slow cluster startup.
[1.6.0] - 2026-07-09
Added
- Preview complete rendered configurations before pushing. Follow live push progress and inspect device output or failure details in the same dialog.
[1.5.0] - 2026-07-09
Added
- Prometheus metrics: monitor cluster health, fleet capacity, tasks, sessions,
and dependencies through
/metrics, using an API key with Fabric read access. - Operator console (
msh): inspect platform state, recover stuck tasks and sessions, and create support bundles with secrets masked, even when the UI or API is unavailable. Includes command help, completion, and scripting; recovery actions require confirmation and are audited.
[1.4.0] - 2026-07-09
Added
- A single Username & Password credential type and a protected None entry for connections requiring no stored secret.
Upgrade notes
- Existing paired credentials migrate automatically to Username & Password.
[1.3.1] - 2026-07-08
Changed
- Policy pages use domain tabs with rules, templates, and stacks. Earlier links redirect to the corresponding tabs.
Fixed
- Undelivered tasks and jobs recover promptly; automation and AI tasks recover when their node disappears. Late updates cannot reopen completed work.
- Session-end notifications are no longer duplicated.
- Long-running database sessions are no longer closed by background cleanup.
- Topology separates Core clients from Workers more clearly.
[1.3.0] - 2026-07-07
Added
- Fabric: a unified fleet view of Cores, Workers, Sensors, and Proxies, with component details, Proxy sessions, and a live regional Topology view.
- Configuration workflows: templates, stacks, resource variables, preview, and device pushes. Config policies assign stacks; pushes appear in History and can be triggered by automation.
Changed
- Rulesets move to Policies, Tasks to Diagnostics, and Task Types to System. Fabric replaces separate component and Collector pages; old links redirect.
Fixed
- Configuration pushes handle timeouts, long lines, and concurrent results reliably.
- Duplicate policies and templates produce clear errors.
- Fleet views recover from temporary connection failures and show readable uptime.
Security
- More granular feature permissions, including dedicated Fabric read access.
- Configuration pushes send the privileged password only when the device asks.
[1.2.0] - 2026-07-05
Added
- Remote Workers, Sensors, and Proxies report their running software versions.
- Fact policies validate assertion paths while editing.
Changed
- Configuration moves from Settings to Manage; old links redirect.
- The combined session policy tab is renamed Access/Recording.
Fixed
- Facts stay consistent as types change or are disabled, with validation of collected data.
- Forms refresh dropdown choices when opened.
- Recording stores handle duplicate names, concurrent usage, and retries reliably; stores in use cannot be reconfigured. Skip rules ignore unused storage options.
- Users with catalog permissions can access Manage.
Security
- Recording-store connection tests require permission, validate credential types, and limit exposed error details.
[1.1.0] - 2026-07-05
Added
- Recording policies and stores: select sessions to record, their destination, and retention. Supports local storage, Amazon S3, and Azure Blob, with a default local store and record-all rule.
- Govern: access, recording, fact, and security policies in one area.
- High availability: multi-Core failover, multi-region deployments, and Kubernetes manifests with graceful draining and readiness checks.
Changed
- Policies replace global recording-storage settings and the setup wizard’s storage step. Unrecorded sessions clearly indicate that replay is unavailable.
- Access Policy replaces Session Policy; old Settings links redirect to Govern.
- Multi-node deployments require a shared database and application cache.
- Rolling upgrades are supported within a major version unless a release requires a cold upgrade; cross-major cluster upgrades require a cold upgrade.
Fixed
- Recordings remain complete and replayable after Worker crashes or node loss.
- Scheduled tasks run once across leader failover, without duplicate or missed runs.
Security
- Stronger guest-session protection against denial-of-service, brute-force, and stale access; Fact policies enforce resource and input limits.
- Generated administrator passwords use an owner-only file, and service tokens are kept out of the environment.
- API rate limiting is more reliable.
[1.0.0] - 2026-06-28
Initial release of MisterShell for browser-based infrastructure access.
Added
- Remote access: SSH, RDP, VNC, cloud, Kubernetes, and database sessions, with recording, replay, guest sharing, observation, and shell profiles.
- Access and identity: session/command policies, location-scoped roles, SAML, OIDC, LDAP, group mappings, login lockout, and encrypted credentials.
- Inventory: locations, tags, versioned facts, configuration snapshots, compliance checks, health metrics, and change history.
- Automation and AI: event-driven playbooks, diagnostics, AI assistants, Quick Assist, and usage limits.
- Monitoring: licensed IDS and log collection, security/API audit logs, and external forwarding.
- Reporting: scoped reports, AI summaries, dashboards, live activity, and Notes.
- Deployment: all-in-one or distributed components, external database/cache support, guest proxies, offline licensing, and guided onboarding.