This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Moderate signalThe private account setting that leaked usernames via the /json API endpoint has been fixed in version 4.5.4.
Why it matters: Fixes a security issue (severity 90) affecting the /json API, preventing username leakage; critical for developers and SREs managing API access.
Summary
AI summaryUpdates Links, HTML, and https://blog.chevereto.com/2026/04/08/chevereto-4-5/ across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes private account setting leaking username on /json endpoint Fixes private account setting leaking username on /json endpoint Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Redesigns default Contact page (HTML) Redesigns default Contact page (HTML) Source: llm_adapter@2026-06-04 Confidence: high |
— |
Security Fixes
- [Security] Fix private account setting leaking username on /json endpoint.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About chevereto
The mature, battle-tested, high-end, OG self-hosted image and video hosting solution trusted since 2007. Build your own Flickr or Imgur-style media sharing platform with complete control over your content, data, and platform rules.
Related context
Related tools
Beta — feedback welcome: [email protected]