This release includes 2 breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
ReleasePort's take
Light signalChevereto 4.5.5 adds a new CHEVERETO_TENANTS_DB_ISOLATION_MODE configuration option and several UI enhancements, while fixing multiple bugs affecting URLs, upload editing, theme overrides, and email‑dependent flows.
Why it matters: The release introduces configurable tenant database isolation (severity 20) and resolves critical UI/flow defects (severity 40) that impact user experience and system stability; operators should review the new setting and apply the bug fixes promptly.
Summary
AI summaryUpdates Links, Elevado, and https://blog.chevereto.com/2026/04/08/chevereto-4-5/ across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds CHEVERETO_TENANTS_DB_ISOLATION_MODE configuration option. Adds CHEVERETO_TENANTS_DB_ISOLATION_MODE configuration option. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Adds configurable system notices display feature. Adds configurable system notices display feature. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Adds links to user manual and admin manual on dashboard. Adds links to user manual and admin manual on dashboard. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Adds warning to account resend activation when email delivery isn't configured. Adds warning to account resend activation when email delivery isn't configured. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Adds warning to password forgot when email delivery isn't configured. Adds warning to password forgot when email delivery isn't configured. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Adds warning to signup when email delivery isn't configured. Adds warning to signup when email delivery isn't configured. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Disables guest uploads by default. Disables guest uploads by default. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Disables user self-signup by default. Disables user self-signup by default. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Disables email‑dependent settings when no email provider is configured. Disables email‑dependent settings when no email provider is configured. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes wrong user URL when website mode personal is enabled. Fixes wrong user URL when website mode personal is enabled. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Fixes missing album options when editing upload item. Fixes missing album options when editing upload item. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Fixes theme overrides not working for dashboard views. Fixes theme overrides not working for dashboard views. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Fixes theme overrides not working for settings views. Fixes theme overrides not working for settings views. Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
Chevereto 4.5.5 (2026-07-10)
- Added CHEVERETO_TENANTS_DB_ISOLATION_MODE
- Added configurable system notices display
- Added links to user manual and admin manual on dashboard
- Added warning to account resend activation when email delivery isn't configured
- Added warning to password forgot when email delivery isn't configured
- Added warning to signup when email delivery isn't configured
- Disabled email-dependent settings when no email provider is configured
- Disabled guest uploads by default
- Disabled user self-signup by default
- Fixed bug with wrong user URL when website mode personal is enabled
- Fixed bug with missing album options when editing upload item
- Fixed bug with theme overrides not working for overrides/views/dashboard/*
- Fixed bug with theme overrides not working for overrides/views/settings/*
- Improved email settings validation and error handling
Links
Breaking Changes
- Disabled guest uploads by default (CHEVERETO_ALLOW_GUEST_UPLOADS set to false)
- Disabled user self‑signup by default (CHEVERETO_ALLOW_SELF_SIGNUP set to false)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About chevereto
The mature, battle-tested, high-end, OG self-hosted image and video hosting solution trusted since 2007. Build your own Flickr or Imgur-style media sharing platform with complete control over your content, data, and platform rules.
Related context
Related tools
Beta — feedback welcome: [email protected]