This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+5 more
Affected surfaces
ReleasePort's take
Moderate signalVersion 6.1.5 of Bolt CMS fixes a security flaw that allowed SSRF through unchecked followed redirects.
Why it matters: The release prevents server‑side request forgery via uncontrolled redirect chains; operators running prior versions should upgrade immediately to eliminate the vulnerability.
Summary
AI summaryPrevent SSRF due to unchecked followed redirects
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Prevents SSRF via unchecked followed redirects Prevents SSRF via unchecked followed redirects Source: llm_adapter@2026-07-13 Confidence: high |
— |
Full changelog
Note: this release includes a security-related fix!
- Prevent SSRF due to unchecked followed redirects (@Vondry)
Full Changelog: https://github.com/bolt/core/compare/6.1.4...6.1.5
Security Fixes
- Prevent SSRF due to unchecked followed redirects
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Bolt CMS
Content Management Tool, which strives to be as simple and straightforward as possible.
Beta — feedback welcome: [email protected]