Skip to content

chevereto

v4.5.4 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

aws chunked-uploads gallery image-host image-hosting image-sharing
+14 more
image-sharing-website media-embedding media-sharing multi-language multi-storage multi-tenancy photo-gallery photo-gallery-application photo-management photos s3 self-hosted video-hosting video-sharing

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

The private account setting that leaked usernames via the /json API endpoint has been fixed in version 4.5.4.

Why it matters: Fixes a security issue (severity 90) affecting the /json API, preventing username leakage; critical for developers and SREs managing API access.

Summary

AI summary

Updates Links, HTML, and https://blog.chevereto.com/2026/04/08/chevereto-4-5/ across a mixed release.

Changes in this release

Security Critical

Fixes private account setting leaking username on /json endpoint

Fixes private account setting leaking username on /json endpoint

Source: llm_adapter@2026-06-04

Confidence: high

Feature Low

Redesigns default Contact page (HTML)

Redesigns default Contact page (HTML)

Source: llm_adapter@2026-06-04

Confidence: high

Full changelog

Security Fixes

  • [Security] Fix private account setting leaking username on /json endpoint.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track chevereto

Get notified when new releases ship.

Sign up free

About chevereto

The mature, battle-tested, high-end, OG self-hosted image and video hosting solution trusted since 2007. Build your own Flickr or Imgur-style media sharing platform with complete control over your content, data, and platform rules.

All releases →

Beta — feedback welcome: [email protected]