This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Developer Productivity
✓ No known CVEs patched
This release patches 1 known CVE
Topics
bun
conversion
convert
converter
document-conversion
elysia
+6 more
file-conversion
file-converter
pdf-converter
self-hosted
tailwindcss
typescript
Affected surfaces
rce_ssrf
Summary
AI summaryUpdates feat, fix, and forky across a mixed release.
Full changelog
What's Changed
- feat: PDF to DOCX using LibreOffice, fixes #425 by @ToniRos in https://github.com/C4illin/ConvertX/pull/510
- fix: allow dynamic server port via environment variable by @giuliolibrando in https://github.com/C4illin/ConvertX/pull/530
- feat: update to debian testing (forky) by @C4illin in https://github.com/C4illin/ConvertX/pull/534
- fix(assimp): pass -f so non-extension targets work by @dantebarbieri in https://github.com/C4illin/ConvertX/pull/557
- security: fix path traversal vulnerability in conversion API by @Fluxmux in https://github.com/C4illin/ConvertX/pull/532
New Contributors
- @ToniRos made their first contribution in https://github.com/C4illin/ConvertX/pull/510
- @giuliolibrando made their first contribution in https://github.com/C4illin/ConvertX/pull/530
- @dantebarbieri made their first contribution in https://github.com/C4illin/ConvertX/pull/557
- @Fluxmux made their first contribution in https://github.com/C4illin/ConvertX/pull/532
Full Changelog: https://github.com/C4illin/ConvertX/compare/v0.17.0...v0.18.0
Security Fixes
- CVE-2026-XXXXX — path traversal vulnerability fixed in conversion API
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]