Skip to content

Bolt CMS

v6.1.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 14d Documentation
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

api api-platform bolt cms doctrine headless
+5 more
multilingual php symfony twig vue

Affected surfaces

rce_ssrf

ReleasePort's take

Moderate signal
editorial:auto 13d

Version 6.1.5 of Bolt CMS fixes a security flaw that allowed SSRF through unchecked followed redirects.

Why it matters: The release prevents server‑side request forgery via uncontrolled redirect chains; operators running prior versions should upgrade immediately to eliminate the vulnerability.

Summary

AI summary

Prevent SSRF due to unchecked followed redirects

Changes in this release

Security Critical

Prevents SSRF via unchecked followed redirects

Prevents SSRF via unchecked followed redirects

Source: llm_adapter@2026-07-13

Confidence: high

Full changelog

Note: this release includes a security-related fix!

  • Prevent SSRF due to unchecked followed redirects (@Vondry)

Full Changelog: https://github.com/bolt/core/compare/6.1.4...6.1.5

Security Fixes

  • Prevent SSRF due to unchecked followed redirects

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Bolt CMS

Get notified when new releases ship.

Sign up free

About Bolt CMS

Content Management Tool, which strives to be as simple and straightforward as possible.

All releases →

Related context

Beta — feedback welcome: [email protected]