Skip to content

chartbrew

v5.2.3 Security

This release includes 10 security fixes for security teams reviewing exposed deployments.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 10 known CVEs

Topics

analytics api chartjs charts web data-visualization
+11 more
firebase firebase-firestore firestore mongodb mysql nodejs postgresql react reactjs realtime-database redux

Affected surfaces

auth rbac crypto_tls

ReleasePort's take

Moderate signal
editorial:auto 7d

Chartbrew v5.2.3 hardens tenant isolation and encrypts share tokens, session authentication, dashboard passwords, SSH credentials, file operations, API policies, MongoDB processing, SQL/ClickHouse queries, and adds basic auth to the BullMQ admin UI.

Why it matters: Security severity scores range from 55‑90; these changes block cross‑project access, protect secrets, and enforce authenticationβ€”critical for operators managing multi‑tenant environments.

Summary

AI summary

Updates πŸ” Security patches, βš™οΈ Configuration changes, and πŸ› Bug fixes across a mixed release.

Changes in this release

Security Critical

Strengthened tenant boundaries to prevent cross-project access.

Strengthened tenant boundaries to prevent cross-project access.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security High

Migrated public dashboard and chart share tokens to `CB_ENCRYPTION_KEY`.

Migrated public dashboard and chart share tokens to `CB_ENCRYPTION_KEY`.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security High

Rejected session tokens signed with the legacy `CB_SECRET`.

Rejected session tokens signed with the legacy `CB_SECRET`.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security High

Encrypted dashboard passwords and added rate limiting to password-protected dashboards.

Encrypted dashboard passwords and added rate limiting to password-protected dashboards.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security High

Encrypted SSH tunnel credentials and prevented secrets from being returned by the API.

Encrypted SSH tunnel credentials and prevented secrets from being returned by the API.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security High

Restricted connection file operations to Chartbrew-managed storage.

Restricted connection file operations to Chartbrew-managed storage.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security High

Tightened private-network policies for API connections.

Tightened private-network policies for API connections.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security Medium

Hardened MongoDB variable processing.

Hardened MongoDB variable processing.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security Medium

Added additional PostgreSQL and ClickHouse query guards.

Added additional PostgreSQL and ClickHouse query guards.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Security Medium

Protected the BullMQ admin dashboard with HTTP Basic Authentication.

Protected the BullMQ admin dashboard with HTTP Basic Authentication.

Source: llm_adapter@2026-07-19

Confidence: high

β€”
Bugfix Medium

Prevented snapshot schedules from being saved or executed without an email recipient or enabled integration.

Prevented snapshot schedules from being saved or executed without an email recipient or enabled integration.

Source: granite4.1:30b@2026-07-19-audit

Confidence: low

β€”
Bugfix Low

Fixed ClickHouse query formatting when processing variables.

Fixed ClickHouse query formatting when processing variables.

Source: granite4.1:30b@2026-07-19-audit

Confidence: low

β€”
Full changelog

Changelog

[!WARNING]
This version includes important security improvements. Please update to this version as soon as possible.

πŸ” Security patches

  • Strengthened tenant boundaries to prevent cross-project access.
  • Migrated public dashboard and chart share tokens to CB_ENCRYPTION_KEY.
  • Rejected session tokens signed with the legacy CB_SECRET.
  • Encrypted dashboard passwords and added rate limiting to password-protected dashboards.
  • Encrypted SSH tunnel credentials and prevented secrets from being returned by the API.
  • Restricted connection file operations to Chartbrew-managed storage.
  • Tightened private-network policies for API connections.
  • Hardened MongoDB variable processing.
  • Added additional PostgreSQL and ClickHouse query guards.
  • Protected the BullMQ admin dashboard with HTTP Basic Authentication.

πŸ› Bug fixes

  • Prevented snapshot schedules from being saved or executed without an email recipient or enabled integration.
  • Fixed ClickHouse query formatting when processing variables.

βš™οΈ Configuration changes

  • Added CB_BULLMQ_USERNAME and CB_BULLMQ_PASSWORD for protecting the BullMQ dashboard at /apps/queues.
  • Added CB_ALLOW_LEGACY_SHARE_TOKENS as a temporary migration option for existing share links signed with CB_SECRET.
  • Local .env installations automatically generate BullMQ credentials when they are not configured.

Contributors

Security Fixes

  • Strengthened tenant boundaries to prevent cross-project access
  • Migrated public dashboard and chart share tokens to CB_ENCRYPTION_KEY
  • Rejected session tokens signed with legacy CB_SECRET
  • Encrypted dashboard passwords and added rate limiting to password-protected dashboards
  • Encrypted SSH tunnel credentials and prevented secrets from being returned by the API
  • Restricted connection file operations to Chartbrew-managed storage
  • Tightened private-network policies for API connections
  • Hardened MongoDB variable processing
  • Added additional PostgreSQL and ClickHouse query guards
  • Protected BullMQ admin dashboard with HTTP Basic Authentication

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track chartbrew

Get notified when new releases ship.

Sign up free

About chartbrew

Open-source reporting platform to build and share live dashboards from APIs, SQL and NoSQL databases, with powerful AI assistant, scheduling, and embeddable charts

All releases β†’

Related context

Related tools

Beta — feedback welcome: [email protected]