Skip to content

chatwoot

v4.16.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

actioncable chat-widget conversation customer-support web design
+12 more
docker heroku intercom javascript livechat opensource rails ruby sass vuejs whatsapp zendesk

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Fixes WhatsApp coexistence bugs, rate‑limit security flaws, and performance regression in report reopen‑rate calculations.

Full changelog

ChangeLog

  • Voice call dashboard and WhatsApp calling fixes.
  • Captain generation path, overview, and multimodal session fixes.
  • WhatsApp coexistence, BSUID, phone lookup, and reply-window fixes.
  • Security/API fixes for rate limits, agent quotas, hook deletion, and token access.
  • Message rendering, widget transcript, and sender preview fixes.
  • Dashboard stability fixes for channel lists, calls, and assignment dropdowns.
  • Performance fix for report reopen-rate calculations.

This release fixes issues in the new spam-protection gating for Public API and webhooks along with agent assignment dropdown. If you are on v4.16.0 and notice problems, please upgrade to this version.

Security Fixes

  • Security/API fixes for rate limits, agent quotas, hook deletion, and token access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track chatwoot

Get notified when new releases ship.

Sign up free

About chatwoot

Open-source live-chat, email support, omni-channel desk. An alternative to Intercom, Zendesk, Salesforce Service Cloud etc.

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]