This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
ReleasePort's take
Light signalVersion 3.22.0 now invalidates sessions when a user is disabled.
Why it matters: Security: immediately enforce session revocation for any newly‑disabled users to prevent unauthorized access.
Summary
AI summarySessions are now invalidated when a user is disabled.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Invalidate sessions for disabled users Invalidate sessions for disabled users Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
API improvements to support MCP protocol API improvements to support MCP protocol Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
What's Changed
- Feat: API improvements to support MCP protocol by @dignajar in https://github.com/bludit/bludit/pull/1707
- Fix: Invalidate sessions for disabled users (GHSA-q42h-wpg8-5wwf) thanks for report it @N0tFix3d
Security Fixes
- GHSA-q42h-wpg8-5wwf — Invalidate sessions for disabled users
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Bludit
Build a site or blog in seconds. Bludit uses flat-files (text files in JSON format) to store posts and pages.
Beta — feedback welcome: [email protected]