v1.18.1

Klavis-AI/klavisv1.18.1Apr 30, 2026by github-actions[bot]

AI Summary

This release prioritizes security fixes, specifically preventing code injection and open redirect attacks, while adding support for KLV data handling and a new HLS CDN secret configuration for simplified deployment.

Key Highlights

  • Security fixes preventing code injection in hooks and open redirect attacks in HLS and WebRTC
  • Support for reading and writing Key-Length Variable (KLV) data
  • New `hlsCDNSecret` configuration option for easier CDN integration
  • Temporary redirects instead of permanent redirects to prevent unwanted caching
  • RPI Camera control handling updates for libcamera 0.7.0 compatibility

New Features

  • Support for reading and writing KLV
  • hlsCDNSecret configuration
  • Allow caching non-low-latency playlists

Full Release Notes

## Fixes and improvements

General

* prevent code injection in case of MTX_QUERY in hooks (https://github.com/bluenviron/mediamtx/issues/5707) When MTX_QUERY is used explicitly in hooks, for instance "curl http://something/?$MTX_QUERY", it can be used to inject arbitrary commands. MTX_QUERY is now url-encoded to prevent any abuse regardless of the configuration.
* use temporary redirects instead of permanent redirects (https://github.com/bluenviron/mediamtx/issues/5710) this prevents unwanted caching.

HLS

* prevent open redirect attacks (https://github.com/bluenviron/mediamtx/issues/5708)
* support reading and writing KLV (https://github.com/bluenviron/mediamtx/issues/5604)
* add hlsCDNSecret (https://github.com/bluenviron/mediamtx/issues/5716) this allows to serve HLS streams behind a CDN in a simplified way, compatible with the new HLS session system.
* add public attribute to cache-control header (https://github.com/bluenviron/gohlslib/issues/349)
* allow caching non-low-latency playlists (https://github.com/bluenviron/gohlslib/issues/350)

WebRTC

* prevent open redirect attacks (https://github.com/bluenviron/mediamtx/issues/5708)

RPI Camera

* Merge request->controls instead of overwriting (https://github.com/bluenviron/mediamtx-rpicamera/issues/97) libcamera 0.7.0 is more strict about changing controls; assignment is no longer allowed since https://github.com/raspberrypi/libcamera/commit/310cd8bc0756717cde97fe5b083926f6d6931f58 Instead, we use the merge call with overwrite.

## Security

Binaries are compiled from source code by the [Release workflow](https://github.com/bluenviron/mediamtx/actions/workflows/release.yml), which is a fully-visible process that prevents any change or external interference in produced artifacts.

Checksums of binaries are also published in a public blockchain by using [GitHub Attestations](https://docs.github.com/en/actions/concepts/security/artifact-attestations), and they can be verified by running:

```
ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx
```

You can verify checksums of binaries by downloading `checksums.sha256` and running:

```
cat checksums.sha256 | grep "$(ls mediamtx_*)" | sha256sum --check
```