This release includes 6 security fixes for security teams reviewing exposed deployments.
Topics
+9 more
Affected surfaces
ReleasePort's take
Moderate signalVersion v1.4.2 introduces a high‑severity patch for the js-cookie library and adds TOFU host‑key verification for SSH connections.
Why it matters: Patches a high‑severity (severity 90) advisory in js-cookie; implements trust‑on‑first‑use SSH verification, affecting security posture.
Summary
AI summaryUpdates Security & access, Inventory & guests, and Backups & reports across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Patches high‑severity js-cookie advisory by bumping the library. Patches high‑severity js-cookie advisory by bumping the library. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Security | High |
Implements TOFU host‑key verification on the ssh2 path. Implements TOFU host‑key verification on the ssh2 path. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Security | High |
Conducts a security hardening sprint closing critical findings and follow‑ups. Conducts a security hardening sprint closing critical findings and follow‑ups. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Medium |
Adds warm migration for VMware sources with CBT, no data loss. Adds warm migration for VMware sources with CBT, no data loss. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Medium |
Adds local node-to-node VM migration from the Guests tab. Adds local node-to-node VM migration from the Guests tab. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Medium |
Adds in-browser SPICE console for QEMU VMs alongside noVNC. Adds in-browser SPICE console for QEMU VMs alongside noVNC. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Medium |
Adds CRUSH topology view in the Ceph tab with read‑only tree and pool details. Adds CRUSH topology view in the Ceph tab with read‑only tree and pool details. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Medium |
Adds working OSD flag toggles in full cluster config view. Adds working OSD flag toggles in full cluster config view. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Medium |
Introduces role‑level default RBAC scope inherited by all assignments of that role. Introduces role‑level default RBAC scope inherited by all assignments of that role. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Medium |
Introduces pull‑based threshold evaluation with silence sync for alerts. Introduces pull‑based threshold evaluation with silence sync for alerts. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Shows a badge for serial / headless VMs instead of looping on failing screenshot. Shows a badge for serial / headless VMs instead of looping on failing screenshot. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Adds SSO‑only login policy for OIDC, hiding the local form. Adds SSO‑only login policy for OIDC, hiding the local form. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Adds local TOTP two‑factor authentication with admin enforcement policy. Adds local TOTP two‑factor authentication with admin enforcement policy. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Shows real local backup time and Proxmox‑style columns in reports. Shows real local backup time and Proxmox‑style columns in reports. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Explains why the guest Backups tab is empty (no connected PBS or snapshots). Explains why the guest Backups tab is empty (no connected PBS or snapshots). Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Allows cloning a VM from a snapshot restore point. Allows cloning a VM from a snapshot restore point. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Resolves guest VLANs from host bond sub‑interfaces for correct tagging. Resolves guest VLANs from host bond sub‑interfaces for correct tagging. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Dims the guest icon when a VM is off for color‑blind legibility. Dims the guest icon when a VM is off for color‑blind legibility. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Makes dashboard widgets respect appearance settings (font size, corner rounding, shared gauge). Makes dashboard widgets respect appearance settings (font size, corner rounding, shared gauge). Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Keeps tree sections open when clicking PROXMOX VE / NETWORK headers. Keeps tree sections open when clicking PROXMOX VE / NETWORK headers. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes partial-VM cleanup leaking target VMID after failed conversion. Fixes partial-VM cleanup leaking target VMID after failed conversion. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Bugfix | Medium |
Restores "Run now" functionality that was returning an HTML 404. Restores "Run now" functionality that was returning an HTML 404. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Bugfix | Low |
Enables resuming paused VMs and allows dots in tags. Enables resuming paused VMs and allows dots in tags. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Bugfix | Low |
Ensures silences are respected in the home dashboard widget. Ensures silences are respected in the home dashboard widget. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
Full changelog
ProxCenter v1.4.2
Feature release: warm migration for VMware (no data loss), in-browser SPICE consoles, a Ceph CRUSH topology view, role-level RBAC scopes, SSO-only and local 2FA policies, plus a security hardening sprint.
Migration
- Warm migration for VMware sources (CBT). VMware VMs migrate with changed-block tracking and a final delta sync, so there is no data loss on large or busy disks. Covers ESXi-direct and vCenter (including vSAN), single and bulk, with a go/no-go preflight and SOAP-session keepalive (#395).
- Local migration from the cluster Guests tab (node-to-node), instead of forcing cross-cluster only (#388).
- Partial-VM cleanup no longer leaks the target VMID after a failed conversion (#403).
Consoles
- In-browser SPICE console for QEMU VMs, alongside noVNC (#390).
- Serial / headless VMs show a badge instead of looping on a failing screenshot (#375).
Ceph
- CRUSH topology view in the cluster Ceph tab: read-only CRUSH tree with details and pools (#407).
- Full cluster config with working OSD flag toggles (#405).
Security & access
- Security hardening sprint: critical findings closed plus follow-ups (#369), TOFU host-key verification on the ssh2 path (#372), per-connection ws-proxy TLS and Dependabot overrides (#371), js-cookie bumped to clear a high-severity advisory (#346), Node 26 pipeline hardening for XCP-ng / Hyper-V / Nutanix (#345).
- Role-level default RBAC scope, inherited by every assignment of that role (#386).
- SSO-only login policy for OIDC (hide the local form, force the SSO redirect) (#362), plus an issuer fix for manual endpoint overrides (#361).
- Local TOTP two-factor with an admin enforcement policy (#351).
- VM User role gains the read access the Inventory needs to load (#387).
- Standalone hosts behind NAT: node management connects to the public host, not the private interface (#385).
Backups & reports
- Reports and notifications overhaul: connection scoping, backup report polish, per-category severity, and an event-email rework (English copy, task-log details, one mail per event) (#384).
- Empty guest Backups tab now explains why (no connected PBS vs no snapshots) (#399).
- "Run now" works again (a missing route returned an HTML 404) (#398).
- Real local backup time and Proxmox-style columns (#382), and legacy maxfiles is translated to prune-backups (#342).
Inventory & guests
- Clone a VM from a snapshot restore point, choosing a snapshot as the clone source (#412).
- Guest VLANs resolved from host bond sub-interfaces so tagged guests group correctly (#391).
- Resume paused VMs, allow dots in tags (#409), and the guest icon dims when off for color-blind legibility (#411).
- Dashboard widgets honor the appearance settings: font-size, corner-rounding, shared gauge (#377).
- Tree sections stay open when clicking the PROXMOX VE / NETWORK headers (#367).
Alerts
- Pull-based threshold evaluation with silence sync (#365); silences are respected in the home dashboard widget (#368).
Dependencies
- Routine bumps (@mui/lab, tsx, @tailwindcss/postcss, trivy-action, sonarqube-scan-action) and an SSO group-name trim fix for LDAP / OIDC mapping (#343).
Docker Images
docker pull ghcr.io/adminsyspro/proxcenter-frontend:v1.4.2
docker pull ghcr.io/adminsyspro/proxcenter-orchestrator:v1.4.2
docker pull ghcr.io/adminsyspro/proxcenter-weasyprint:v1.4.2
Security Fixes
- TOFU host‑key verification on ssh2 path (#372)
- Per‑connection ws‑proxy TLS hardening (#371)
- js-cookie upgraded to clear high‑severity advisory (#346)
- Node 26 pipeline hardened for XCP‑ng / Hyper‑V / Nutanix (#345)
- Role‑level default RBAC scope enforcement (#386)
- SSO‑only login policy with admin‑enforced local TOTP (#351)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]