This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 22d
Documentation
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
api
api-platform
bolt
cms
doctrine
headless
+5 more
multilingual
php
symfony
twig
vue
Affected surfaces
auth
rce_ssrf
Summary
AI summaryFixes SQL injection, SSRF, unpublished content leakage, and open redirect vulnerabilities.
Full changelog
Note: this release includes several security-related fixes!
- Fix SQL injection in ListFormatHelper (@Vondry)
- Prevent SSRF in upload-from-URL and embed endpoint (@Vondry)
- Filter unpublished/viewless content from the public Relation API (@Vondry)
- Block open redirect on login endpoint (@0xmgaye, fix by @bobvandevijver)
What's Changed
- Bump dependencies by @bobvandevijver in https://github.com/bolt/core/pull/3730
- Bump http-proxy-middleware from 2.0.9 to 2.0.10 by @dependabot[bot] in https://github.com/bolt/core/pull/3740
- Bump undici from 6.26.0 to 6.27.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3737
- Bump launch-editor from 2.14.0 to 2.14.1 by @dependabot[bot] in https://github.com/bolt/core/pull/3731
- Bump locutus from 2.0.39 to 3.0.25 by @dependabot[bot] in https://github.com/bolt/core/pull/3744
Full Changelog: https://github.com/bolt/core/compare/6.1.3...6.1.4
Security Fixes
- Fix SQL injection in ListFormatHelper
- Prevent SSRF in upload-from-URL and embed endpoint
- Block open redirect on login endpoint
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Bolt CMS
Content Management Tool, which strives to be as simple and straightforward as possible.
Beta — feedback welcome: [email protected]