发布日期: 2026-03-12
版本号: 1.19.1

Cryptomator 1.19.1发布包含多项重要更新。安全方面修复了多个漏洞,包括可能存在的中间人攻击风险、默认禁用对Hub的未加密HTTP连接、修复从任意路径加载主密钥文件的问题,并确保未配置插件目录时正确禁用插件搜索。新功能方面,Cryptomator Hub在解锁保险库时引入了首次使用时信任机制。同时修复了在macOS上显示保险库时Finder窗口打开两次的问题,以及由于Linux上密钥服务检测失败导致应用无法启动的问题。其他更改包括固定appimagetool版本、更新翻译及升级了多个依赖库。发布物提供了SHA-256校验和及GPG签名验证方法。

更新内容 (中文)

欲了解变更的完整视图,请阅读更新日志

安全修复 🚨

  • Cryptomator Hub:修复了可能通过被篡改的保管库配置进行的中间人攻击(#4179,CVE-2026-32303
  • 默认禁止使用未加密的HTTP连接到Hub(CVE-2026-32309
  • 修复了从任意路径加载主密钥文件的问题(#4180,CVE-2026-32310
  • 修复了未配置插件目录不会禁用插件搜索的问题(#4176

新功能 🎉

  • Cryptomator Hub:解锁Hub保管库时采用首次使用时信任(#4179

错误修复 🐛

  • 修复了在macOS上显示保管库时Finder窗口打开两次的问题(#4177
  • 修复了因Linux上密钥服务检测失败导致应用无法启动的问题(#4175

其他变更 📎

  • 固定appimagetool版本(#4181
  • 更新了翻译
  • 更新了依赖项:
    • org.cryptomator:integrations-api 从 1.8.0-beta1 升级到 1.8.0
    • org.cryptomator:integrations-linux 从 1.7.0-beta4 升级到 1.7.0
    • org.cryptomator:integrations-mac 从 1.5.0-beta3 升级到 1.5.0

完整更新日志:https://github.com/cryptomator/cryptomator/compare/1.19.0…1.19.1

📜 已关闭的问题和拉取请求列表可在此处查看:此处


💾 发布产物的SHA-256校验和:

c995daa2acd813e1a975d540a1af0dff57700e56c1c541e203117172829dd382 .\cryptomator_1.19.1-0ppa1_amd64.deb
05af34b8c6430d4e033f029eb20071ec718e529715f15e41f91230665d146849 .\cryptomator-1.19.1-aarch64.AppImage
c208184d36b1570e00c2929b3b230679191235742385e883863135ee67e9c581 .\Cryptomator-1.19.1-arm64.dmg
14e3273f02268c6abf9a9962dbf35a01f45f4dd75ea90973af3827fcf88b96cb .\Cryptomator-1.19.1-x64.dmg
08beab0e625339aa8525339388a1317987dc0f2f70d114737cbaf66d0ce62a1a .\Cryptomator-1.19.1-x64.exe
77ff121b725938bc05efaa842cfd7db2bbe0f32ca76c93b98c65b225d226d7fd .\Cryptomator-1.19.1-x64.msi
6acfccb9368731a96c375a1ec26666c93fd5735c03d200b9bf37d6e290a18116 .\cryptomator-1.19.1-x86_64.AppImage

[!TIP] 您可以使用我们的公钥验证所有资产的GPG签名:5811 7AFA 1F85 B3EE C154 677D 615D 449F E6E6 A235

更新内容 (原始)

For a comprehensive view of changes, read the CHANGELOG.

Security Fixes 🚨

  • Cryptomator Hub: Fixed possible man-in-the-middle attack with tampered vault config (#4179, CVE-2026-32303)
  • Disallow unencrypted http connections to hub by default (CVE-2026-32309)
  • Fixed loading of masterkey file from arbitrary paths (#4180, CVE-2026-32310)
  • Fixed not-configured plugin directory does not disable plugin search (#4176)

What’s New 🎉

  • Cryptomator Hub: Trust on first use when unlocking a Hub vault (#4179)

Bugfixes 🐛

  • Fixed Finder window opens twice when revealing vault on macOS (#4177)
  • Fixed app does not start due to secret service detection failure on Linux (#4175)

Other Changes 📎

  • Pin version of appimagetool(#4181)
  • Updated translations
  • Updated dependencies:
    • org.cryptomator:integrations-api from 1.8.0-beta1 to 1.8.0
    • org.cryptomator:integrations-linux from 1.7.0-beta4 to 1.7.0
    • org.cryptomator:integrations-mac from 1.5.0-beta3 to 1.5.0

Full Changelog: https://github.com/cryptomator/cryptomator/compare/1.19.0...1.19.1

📜 List of closed issues and pull requests is available here


💾 SHA-256 checksums of release artifacts:

c995daa2acd813e1a975d540a1af0dff57700e56c1c541e203117172829dd382 .\cryptomator_1.19.1-0ppa1_amd64.deb
05af34b8c6430d4e033f029eb20071ec718e529715f15e41f91230665d146849 .\cryptomator-1.19.1-aarch64.AppImage
c208184d36b1570e00c2929b3b230679191235742385e883863135ee67e9c581 .\Cryptomator-1.19.1-arm64.dmg
14e3273f02268c6abf9a9962dbf35a01f45f4dd75ea90973af3827fcf88b96cb .\Cryptomator-1.19.1-x64.dmg
08beab0e625339aa8525339388a1317987dc0f2f70d114737cbaf66d0ce62a1a .\Cryptomator-1.19.1-x64.exe
77ff121b725938bc05efaa842cfd7db2bbe0f32ca76c93b98c65b225d226d7fd .\Cryptomator-1.19.1-x64.msi
6acfccb9368731a96c375a1ec26666c93fd5735c03d200b9bf37d6e290a18116 .\cryptomator-1.19.1-x86_64.AppImage

[!TIP] You can verify the GPG signature of all assets using our public key: 5811 7AFA 1F85 B3EE C154 677D 615D 449F E6E6 A235.

下载链接