This release includes 10 security fixes for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
ReleasePort's take
Moderate signalChartbrew v5.2.3 hardens tenant isolation and encrypts share tokens, session authentication, dashboard passwords, SSH credentials, file operations, API policies, MongoDB processing, SQL/ClickHouse queries, and adds basic auth to the BullMQ admin UI.
Why it matters: Security severity scores range from 55β90; these changes block crossβproject access, protect secrets, and enforce authenticationβcritical for operators managing multiβtenant environments.
Summary
AI summaryUpdates π Security patches, βοΈ Configuration changes, and π Bug fixes across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Strengthened tenant boundaries to prevent cross-project access. Strengthened tenant boundaries to prevent cross-project access. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | High |
Migrated public dashboard and chart share tokens to `CB_ENCRYPTION_KEY`. Migrated public dashboard and chart share tokens to `CB_ENCRYPTION_KEY`. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | High |
Rejected session tokens signed with the legacy `CB_SECRET`. Rejected session tokens signed with the legacy `CB_SECRET`. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | High |
Encrypted dashboard passwords and added rate limiting to password-protected dashboards. Encrypted dashboard passwords and added rate limiting to password-protected dashboards. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | High |
Encrypted SSH tunnel credentials and prevented secrets from being returned by the API. Encrypted SSH tunnel credentials and prevented secrets from being returned by the API. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | High |
Restricted connection file operations to Chartbrew-managed storage. Restricted connection file operations to Chartbrew-managed storage. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | High |
Tightened private-network policies for API connections. Tightened private-network policies for API connections. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | Medium |
Hardened MongoDB variable processing. Hardened MongoDB variable processing. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | Medium |
Added additional PostgreSQL and ClickHouse query guards. Added additional PostgreSQL and ClickHouse query guards. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Security | Medium |
Protected the BullMQ admin dashboard with HTTP Basic Authentication. Protected the BullMQ admin dashboard with HTTP Basic Authentication. Source: llm_adapter@2026-07-19 Confidence: high |
β |
| Bugfix | Medium |
Prevented snapshot schedules from being saved or executed without an email recipient or enabled integration. Prevented snapshot schedules from being saved or executed without an email recipient or enabled integration. Source: granite4.1:30b@2026-07-19-audit Confidence: low |
β |
| Bugfix | Low |
Fixed ClickHouse query formatting when processing variables. Fixed ClickHouse query formatting when processing variables. Source: granite4.1:30b@2026-07-19-audit Confidence: low |
β |
Full changelog
Changelog
[!WARNING]
This version includes important security improvements. Please update to this version as soon as possible.
π Security patches
- Strengthened tenant boundaries to prevent cross-project access.
- Migrated public dashboard and chart share tokens to
CB_ENCRYPTION_KEY. - Rejected session tokens signed with the legacy
CB_SECRET. - Encrypted dashboard passwords and added rate limiting to password-protected dashboards.
- Encrypted SSH tunnel credentials and prevented secrets from being returned by the API.
- Restricted connection file operations to Chartbrew-managed storage.
- Tightened private-network policies for API connections.
- Hardened MongoDB variable processing.
- Added additional PostgreSQL and ClickHouse query guards.
- Protected the BullMQ admin dashboard with HTTP Basic Authentication.
π Bug fixes
- Prevented snapshot schedules from being saved or executed without an email recipient or enabled integration.
- Fixed ClickHouse query formatting when processing variables.
βοΈ Configuration changes
- Added
CB_BULLMQ_USERNAMEandCB_BULLMQ_PASSWORDfor protecting the BullMQ dashboard at/apps/queues. - Added
CB_ALLOW_LEGACY_SHARE_TOKENSas a temporary migration option for existing share links signed withCB_SECRET. - Local
.envinstallations automatically generate BullMQ credentials when they are not configured.
Contributors
Security Fixes
- Strengthened tenant boundaries to prevent cross-project access
- Migrated public dashboard and chart share tokens to CB_ENCRYPTION_KEY
- Rejected session tokens signed with legacy CB_SECRET
- Encrypted dashboard passwords and added rate limiting to password-protected dashboards
- Encrypted SSH tunnel credentials and prevented secrets from being returned by the API
- Restricted connection file operations to Chartbrew-managed storage
- Tightened private-network policies for API connections
- Hardened MongoDB variable processing
- Added additional PostgreSQL and ClickHouse query guards
- Protected BullMQ admin dashboard with HTTP Basic Authentication
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About chartbrew
Open-source reporting platform to build and share live dashboards from APIs, SQL and NoSQL databases, with powerful AI assistant, scheduling, and embeddable charts
Beta — feedback welcome: [email protected]