Skip to content

Fizzy

vfizzy@bead275 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 4mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

hotwire kanban rails ruby

Affected surfaces

auth deps

Summary

AI summary

Prevent HTML injection through filenames closes a security vulnerability.

Full changelog

What's Changed

  • Prevent HTML injection through filenames by @monorkin in https://github.com/basecamp/fizzy/pull/2709
  • Conditionally disable peer verification for ZIP streaming by @monorkin in https://github.com/basecamp/fizzy/pull/2710

Full Changelog: https://github.com/basecamp/fizzy/compare/[email protected]@bead275

Security Fixes

  • Prevent HTML injection through filenames — closes vulnerability allowing malicious HTML in file names

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Fizzy

Get notified when new releases ship.

Sign up free

About Fizzy

Kanban boards for issue and idea tracking

All releases →

Related context

Beta — feedback welcome: [email protected]