Skip to content

Bolt CMS

v6.1.4 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 22d Documentation
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

api api-platform bolt cms doctrine headless
+5 more
multilingual php symfony twig vue

Affected surfaces

auth rce_ssrf

Summary

AI summary

Fixes SQL injection, SSRF, unpublished content leakage, and open redirect vulnerabilities.

Full changelog

Note: this release includes several security-related fixes!

  • Fix SQL injection in ListFormatHelper (@Vondry)
  • Prevent SSRF in upload-from-URL and embed endpoint (@Vondry)
  • Filter unpublished/viewless content from the public Relation API (@Vondry)
  • Block open redirect on login endpoint (@0xmgaye, fix by @bobvandevijver)

What's Changed

  • Bump dependencies by @bobvandevijver in https://github.com/bolt/core/pull/3730
  • Bump http-proxy-middleware from 2.0.9 to 2.0.10 by @dependabot[bot] in https://github.com/bolt/core/pull/3740
  • Bump undici from 6.26.0 to 6.27.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3737
  • Bump launch-editor from 2.14.0 to 2.14.1 by @dependabot[bot] in https://github.com/bolt/core/pull/3731
  • Bump locutus from 2.0.39 to 3.0.25 by @dependabot[bot] in https://github.com/bolt/core/pull/3744

Full Changelog: https://github.com/bolt/core/compare/6.1.3...6.1.4

Security Fixes

  • Fix SQL injection in ListFormatHelper
  • Prevent SSRF in upload-from-URL and embed endpoint
  • Block open redirect on login endpoint

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Bolt CMS

Get notified when new releases ship.

Sign up free

About Bolt CMS

Content Management Tool, which strives to be as simple and straightforward as possible.

All releases →

Related context

Beta — feedback welcome: [email protected]