Skip to content

ProxCenter

v1.4.2 Security

This release includes 6 security fixes for security teams reviewing exposed deployments.

Published 1mo Virtualization
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 6 known CVEs

Topics

backup-management ceph cluster-management datacenter drs high-availability
+9 more
load-balancing monitoring pbs proxmox pve pve-cluster self-hosted sysadmin virtualization

Affected surfaces

auth rbac deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

Version v1.4.2 introduces a high‑severity patch for the js-cookie library and adds TOFU host‑key verification for SSH connections.

Why it matters: Patches a high‑severity (severity 90) advisory in js-cookie; implements trust‑on‑first‑use SSH verification, affecting security posture.

Summary

AI summary

Updates Security & access, Inventory & guests, and Backups & reports across a mixed release.

Changes in this release

Security Critical

Patches high‑severity js-cookie advisory by bumping the library.

Patches high‑severity js-cookie advisory by bumping the library.

Source: llm_adapter@2026-06-14

Confidence: high

Security High

Implements TOFU host‑key verification on the ssh2 path.

Implements TOFU host‑key verification on the ssh2 path.

Source: llm_adapter@2026-06-14

Confidence: high

Security High

Conducts a security hardening sprint closing critical findings and follow‑ups.

Conducts a security hardening sprint closing critical findings and follow‑ups.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Medium

Adds warm migration for VMware sources with CBT, no data loss.

Adds warm migration for VMware sources with CBT, no data loss.

Source: llm_adapter@2026-06-14

Confidence: high

Feature Medium

Adds local node-to-node VM migration from the Guests tab.

Adds local node-to-node VM migration from the Guests tab.

Source: llm_adapter@2026-06-14

Confidence: high

Feature Medium

Adds in-browser SPICE console for QEMU VMs alongside noVNC.

Adds in-browser SPICE console for QEMU VMs alongside noVNC.

Source: llm_adapter@2026-06-14

Confidence: high

Feature Medium

Adds CRUSH topology view in the Ceph tab with read‑only tree and pool details.

Adds CRUSH topology view in the Ceph tab with read‑only tree and pool details.

Source: llm_adapter@2026-06-14

Confidence: high

Feature Medium

Adds working OSD flag toggles in full cluster config view.

Adds working OSD flag toggles in full cluster config view.

Source: llm_adapter@2026-06-14

Confidence: high

Feature Medium

Introduces role‑level default RBAC scope inherited by all assignments of that role.

Introduces role‑level default RBAC scope inherited by all assignments of that role.

Source: llm_adapter@2026-06-14

Confidence: high

Feature Medium

Introduces pull‑based threshold evaluation with silence sync for alerts.

Introduces pull‑based threshold evaluation with silence sync for alerts.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Shows a badge for serial / headless VMs instead of looping on failing screenshot.

Shows a badge for serial / headless VMs instead of looping on failing screenshot.

Source: llm_adapter@2026-06-14

Confidence: high

Feature Low

Adds SSO‑only login policy for OIDC, hiding the local form.

Adds SSO‑only login policy for OIDC, hiding the local form.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Adds local TOTP two‑factor authentication with admin enforcement policy.

Adds local TOTP two‑factor authentication with admin enforcement policy.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Shows real local backup time and Proxmox‑style columns in reports.

Shows real local backup time and Proxmox‑style columns in reports.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Explains why the guest Backups tab is empty (no connected PBS or snapshots).

Explains why the guest Backups tab is empty (no connected PBS or snapshots).

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Allows cloning a VM from a snapshot restore point.

Allows cloning a VM from a snapshot restore point.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Resolves guest VLANs from host bond sub‑interfaces for correct tagging.

Resolves guest VLANs from host bond sub‑interfaces for correct tagging.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Dims the guest icon when a VM is off for color‑blind legibility.

Dims the guest icon when a VM is off for color‑blind legibility.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Makes dashboard widgets respect appearance settings (font size, corner rounding, shared gauge).

Makes dashboard widgets respect appearance settings (font size, corner rounding, shared gauge).

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Feature Low

Keeps tree sections open when clicking PROXMOX VE / NETWORK headers.

Keeps tree sections open when clicking PROXMOX VE / NETWORK headers.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Bugfix Medium

Fixes partial-VM cleanup leaking target VMID after failed conversion.

Fixes partial-VM cleanup leaking target VMID after failed conversion.

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Restores "Run now" functionality that was returning an HTML 404.

Restores "Run now" functionality that was returning an HTML 404.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Bugfix Low

Enables resuming paused VMs and allows dots in tags.

Enables resuming paused VMs and allows dots in tags.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Bugfix Low

Ensures silences are respected in the home dashboard widget.

Ensures silences are respected in the home dashboard widget.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Full changelog

ProxCenter v1.4.2

Feature release: warm migration for VMware (no data loss), in-browser SPICE consoles, a Ceph CRUSH topology view, role-level RBAC scopes, SSO-only and local 2FA policies, plus a security hardening sprint.

Migration

  • Warm migration for VMware sources (CBT). VMware VMs migrate with changed-block tracking and a final delta sync, so there is no data loss on large or busy disks. Covers ESXi-direct and vCenter (including vSAN), single and bulk, with a go/no-go preflight and SOAP-session keepalive (#395).
  • Local migration from the cluster Guests tab (node-to-node), instead of forcing cross-cluster only (#388).
  • Partial-VM cleanup no longer leaks the target VMID after a failed conversion (#403).

Consoles

  • In-browser SPICE console for QEMU VMs, alongside noVNC (#390).
  • Serial / headless VMs show a badge instead of looping on a failing screenshot (#375).

Ceph

  • CRUSH topology view in the cluster Ceph tab: read-only CRUSH tree with details and pools (#407).
  • Full cluster config with working OSD flag toggles (#405).

Security & access

  • Security hardening sprint: critical findings closed plus follow-ups (#369), TOFU host-key verification on the ssh2 path (#372), per-connection ws-proxy TLS and Dependabot overrides (#371), js-cookie bumped to clear a high-severity advisory (#346), Node 26 pipeline hardening for XCP-ng / Hyper-V / Nutanix (#345).
  • Role-level default RBAC scope, inherited by every assignment of that role (#386).
  • SSO-only login policy for OIDC (hide the local form, force the SSO redirect) (#362), plus an issuer fix for manual endpoint overrides (#361).
  • Local TOTP two-factor with an admin enforcement policy (#351).
  • VM User role gains the read access the Inventory needs to load (#387).
  • Standalone hosts behind NAT: node management connects to the public host, not the private interface (#385).

Backups & reports

  • Reports and notifications overhaul: connection scoping, backup report polish, per-category severity, and an event-email rework (English copy, task-log details, one mail per event) (#384).
  • Empty guest Backups tab now explains why (no connected PBS vs no snapshots) (#399).
  • "Run now" works again (a missing route returned an HTML 404) (#398).
  • Real local backup time and Proxmox-style columns (#382), and legacy maxfiles is translated to prune-backups (#342).

Inventory & guests

  • Clone a VM from a snapshot restore point, choosing a snapshot as the clone source (#412).
  • Guest VLANs resolved from host bond sub-interfaces so tagged guests group correctly (#391).
  • Resume paused VMs, allow dots in tags (#409), and the guest icon dims when off for color-blind legibility (#411).
  • Dashboard widgets honor the appearance settings: font-size, corner-rounding, shared gauge (#377).
  • Tree sections stay open when clicking the PROXMOX VE / NETWORK headers (#367).

Alerts

  • Pull-based threshold evaluation with silence sync (#365); silences are respected in the home dashboard widget (#368).

Dependencies

  • Routine bumps (@mui/lab, tsx, @tailwindcss/postcss, trivy-action, sonarqube-scan-action) and an SSO group-name trim fix for LDAP / OIDC mapping (#343).

Docker Images

docker pull ghcr.io/adminsyspro/proxcenter-frontend:v1.4.2
docker pull ghcr.io/adminsyspro/proxcenter-orchestrator:v1.4.2
docker pull ghcr.io/adminsyspro/proxcenter-weasyprint:v1.4.2

Security Fixes

  • TOFU host‑key verification on ssh2 path (#372)
  • Per‑connection ws‑proxy TLS hardening (#371)
  • js-cookie upgraded to clear high‑severity advisory (#346)
  • Node 26 pipeline hardened for XCP‑ng / Hyper‑V / Nutanix (#345)
  • Role‑level default RBAC scope enforcement (#386)
  • SSO‑only login policy with admin‑enforced local TOTP (#351)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track ProxCenter

Get notified when new releases ship.

Sign up free

About ProxCenter

Modern web interface for Proxmox

All releases →

Related context

Earlier breaking changes

  • v1.4.1 Per-cluster migration cap replaces global cap, removes legacy setting.
  • v1.4.0 ProxCenter v1.4.0 drops SQLite and requires PostgreSQL.

Beta — feedback welcome: [email protected]