Skip to content

Chatto

v0.4.11 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 12d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

chat communication gdpr-compliant privacy-first screensharing video-calls
+1 more
voice-calls

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 10d

The v0.4.11 release fixes several frontend bugs and introduces a high‑severity security change that restricts public server asset access.

Why it matters: A severity 90 security fix limits exposure of public server assets; all teams should apply the update immediately to prevent unauthorized access.

Summary

AI summary

Updates Bug Fixes, 0.4.11, and 2026-07-14 across a mixed release.

Changes in this release

Security Critical

Restrict public server assets to mitigate exposure.

Restrict public server assets to mitigate exposure.

Source: llm_adapter@2026-07-17

Confidence: high

Bugfix Medium

Preserve unusual video aspect ratios in frontend.

Preserve unusual video aspect ratios in frontend.

Source: llm_adapter@2026-07-17

Confidence: high

Bugfix Medium

Add direct thread message routes in frontend.

Add direct thread message routes in frontend.

Source: llm_adapter@2026-07-17

Confidence: high

Bugfix Medium

Support remote‑only sessions in frontend.

Support remote‑only sessions in frontend.

Source: llm_adapter@2026-07-17

Confidence: high

Bugfix Medium

Use origin host for message links in frontend.

Use origin host for message links in frontend.

Source: llm_adapter@2026-07-17

Confidence: high

Bugfix Medium

Use server logo for browser icons in frontend.

Use server logo for browser icons in frontend.

Source: llm_adapter@2026-07-17

Confidence: high

Bugfix Medium

Handle constant wrong‑sequence errors in presence module.

Handle constant wrong‑sequence errors in presence module.

Source: llm_adapter@2026-07-17

Confidence: high

Full changelog

0.4.11 (2026-07-14)

Bug Fixes

  • frontend: add direct thread message routes (#1524) (6f644a0)
  • frontend: preserve unusual video aspect ratios (#1521) (2f845af)
  • frontend: support remote-only sessions (#1530) (af84281)
  • frontend: use origin host for message links (#1526) (1448ecd)
  • frontend: use server logo for browser icons (#1506) (41cffa9)
  • presence: handle constant wrong-sequence errors (#1511) (c27cbee)
  • security: restrict public server assets (#1499) (0a10c3f)

Security Fixes

  • Restrict public server assets to prevent unauthorized access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Chatto

Get notified when new releases ship.

Sign up free

About Chatto

Chat app for teams and communities

All releases →

Related context

Related tools

Earlier breaking changes

  • v0.4.13 Breaks threads usage in direct messages.

Beta — feedback welcome: [email protected]