Skip to content

4gaBoards

v3.3.9 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

agile boards collaboration docker issue-management javascript
+13 more
kanban kanban-boards productivity project-management react real-time realtime redux self-hosted task-management todo todolist trello

Affected surfaces

auth breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 1mo

ReleasePort v3.3.9 patches a critical SSO takeover vulnerability and prevents PII leakage from the /api/users endpoint.

Why it matters: The update eliminates an exploitable mass‑assignment flaw that could hijack accounts (severity 95) and stops authenticated users from disclosing personal data (severity 90). Apply v3.3.9 immediately to protect SSO flows and user privacy.

Summary

AI summary

Fixes SSO takeover and PII leakage vulnerabilities.

Changes in this release

Security Critical

Fixes SSO pre-account takeover/hijacking via mass assignment vulnerability.

Fixes SSO pre-account takeover/hijacking via mass assignment vulnerability.

Source: llm_adapter@2026-06-06

Confidence: high

Security Critical

Fixes mass information disclosure (PII leakage) on /api/users endpoint for authenticated users.

Fixes mass information disclosure (PII leakage) on /api/users endpoint for authenticated users.

Source: llm_adapter@2026-06-06

Confidence: high

Feature Medium

Adds optional email/username fields when adding a new user.

Adds optional email/username fields when adding a new user.

Source: llm_adapter@2026-06-06

Confidence: high

Feature Medium

Reworks user invitation to allow non-admins to invite by full email for boards, projects, etc.

Reworks user invitation to allow non-admins to invite by full email for boards, projects, etc.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Improves InstanceSettings UI updates by properly passing core.id.

Improves InstanceSettings UI updates by properly passing core.id.

Source: llm_adapter@2026-06-06

Confidence: high

Full changelog

Changes since last release:

  • 🐞 fix: SSO Pre-Account Takeover / Hijacking via Mass Assignment - thanks @lucquach 7a79f4c
  • 🐞 fix: InstanceSettings faster UI updates, properly pass core.id 77e9e07
  • 🐞 fix: Mass Information Disclosure (PII Leakage) on /api/users to any authenticated user - thanks @de3erve @lucquach 93099d9
  • 🎨 style: Minor fix 596656e
  • 🌟 feat: Added optional email/username when adding new user 908661e
  • 🌟 feat: Reworked user invitation (board, project etc.) to still allow inviting by email for non-admins - full email has to be provided d0bdbc1
  • 📄 [PATCH] Release 3743680

Install this release using: docker pull ghcr.io/rargames/4gaboards:3.3.9
View the changelog summary on the: 4ga Boards Blog

Security Fixes

  • CVE‑2026‑XXXXX – SSO Pre‑Account Takeover / Hijacking via Mass Assignment
  • CVE‑2026‑XXXXX – Mass Information Disclosure (PII Leakage) on /api/users for any authenticated user

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track 4gaBoards

Get notified when new releases ship.

Sign up free

About 4gaBoards

Straightforward realtime kanban boards management for intuitive task tracking. 4ga Boards features an elegant dark mode, collapsible todo lists, and multitasking tools to supercharge your team's productivity.

All releases →

Related context

Beta — feedback welcome: [email protected]