This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
ReleasePort's take
Moderate signalReleasePort v3.3.9 patches a critical SSO takeover vulnerability and prevents PII leakage from the /api/users endpoint.
Why it matters: The update eliminates an exploitable mass‑assignment flaw that could hijack accounts (severity 95) and stops authenticated users from disclosing personal data (severity 90). Apply v3.3.9 immediately to protect SSO flows and user privacy.
Summary
AI summaryFixes SSO takeover and PII leakage vulnerabilities.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes SSO pre-account takeover/hijacking via mass assignment vulnerability. Fixes SSO pre-account takeover/hijacking via mass assignment vulnerability. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Security | Critical |
Fixes mass information disclosure (PII leakage) on /api/users endpoint for authenticated users. Fixes mass information disclosure (PII leakage) on /api/users endpoint for authenticated users. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Medium |
Adds optional email/username fields when adding a new user. Adds optional email/username fields when adding a new user. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Medium |
Reworks user invitation to allow non-admins to invite by full email for boards, projects, etc. Reworks user invitation to allow non-admins to invite by full email for boards, projects, etc. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Improves InstanceSettings UI updates by properly passing core.id. Improves InstanceSettings UI updates by properly passing core.id. Source: llm_adapter@2026-06-06 Confidence: high |
— |
Full changelog
Changes since last release:
- 🐞 fix: SSO Pre-Account Takeover / Hijacking via Mass Assignment - thanks @lucquach 7a79f4c
- 🐞 fix: InstanceSettings faster UI updates, properly pass core.id 77e9e07
- 🐞 fix: Mass Information Disclosure (PII Leakage) on /api/users to any authenticated user - thanks @de3erve @lucquach 93099d9
- 🎨 style: Minor fix 596656e
- 🌟 feat: Added optional email/username when adding new user 908661e
- 🌟 feat: Reworked user invitation (board, project etc.) to still allow inviting by email for non-admins - full email has to be provided d0bdbc1
- 📄 [PATCH] Release 3743680
Install this release using: docker pull ghcr.io/rargames/4gaboards:3.3.9
View the changelog summary on the: 4ga Boards Blog
Security Fixes
- CVE‑2026‑XXXXX – SSO Pre‑Account Takeover / Hijacking via Mass Assignment
- CVE‑2026‑XXXXX – Mass Information Disclosure (PII Leakage) on /api/users for any authenticated user
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About 4gaBoards
Straightforward realtime kanban boards management for intuitive task tracking. 4ga Boards features an elegant dark mode, collapsible todo lists, and multitasking tools to supercharge your team's productivity.
Related context
Related tools
Beta — feedback welcome: [email protected]