This release includes 1 security fix for security teams reviewing exposed deployments.
Published 4mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
hotwire
kanban
rails
ruby
Affected surfaces
auth
deps
Summary
AI summaryPrevent HTML injection through filenames closes a security vulnerability.
Full changelog
What's Changed
- Prevent HTML injection through filenames by @monorkin in https://github.com/basecamp/fizzy/pull/2709
- Conditionally disable peer verification for ZIP streaming by @monorkin in https://github.com/basecamp/fizzy/pull/2710
Full Changelog: https://github.com/basecamp/fizzy/compare/[email protected]@bead275
Security Fixes
- Prevent HTML injection through filenames — closes vulnerability allowing malicious HTML in file names
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]