This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 23d
Productivity & Wikis
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
brainstorming
collaboration
idea-management
knowledge-base
mental-space
pkm
+5 more
productivity
project-management
visual-thinking
visual-workspace
whiteboard
Affected surfaces
auth
rbac
rce_ssrf
Summary
AI summaryFixed a privilege escalation vulnerability allowing read‑only collaborators to write/delete projects, and fixed an SSRF bypass in the image proxy for IPv4‑mapped IPv6 addresses.
Full changelog
Security
- Fixed a privilege escalation vulnerability (GHSA-v3qr-4v8m-29rh) where a read-only collaborator could perform write and delete operations on a project, including wiping and replacing the entire canvas. Reported by @tonghuaroot.
- Fixed an SSRF bypass (GHSA-cvcr-fcf6-366r) in the image proxy where IPv4-mapped IPv6 addresses (e.g.
[::ffff:7f00:1]) could bypass the private IP blocklist and reach internal services. Reported by @tonghuaroot.
Security Fixes
- GHSA-v3qr-4v8m-29rh — Fixed privilege escalation allowing read‑only collaborators to write and delete project data.
- GHSA-cvcr-fcf6-366r — Fixed SSRF bypass in image proxy for IPv4‑mapped IPv6 addresses.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About ideon
Your project is scattered across too many tools. Map the chaos on an infinite canvas where notes, files, TO-DOs (and more!) finally live together.
Beta — feedback welcome: [email protected]