This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+2 more
Affected surfaces
ReleasePort's take
Light signalCryptPad 2026.5.0 upgrades the Diagram app to Drawio 29.6.7 with sketch theme and mode switcher, adds support for Chinese locales, and bumps chainpad-server to 5.3.0. Release includes 19 incremental improvements across messaging, forms, localization, and editor stability.
Why it matters: Diagram upgraded to Drawio 29.6.7 with sketch theme and mode switcher. Chinese locales zh-Hant, zh-Hans enabled. Chainpad-server 5.3.0 required. Routine upgrade for UX improvements and bugfixes.
Summary
AI summaryDiagram app upgraded to Drawio 29.6.7 with a sketch‑theme default and mode switcher.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Upgrade Diagram app to Drawio 29.6.7. Upgrade Diagram app to Drawio 29.6.7. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Add button to switch diagram modes and themes. Add button to switch diagram modes and themes. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Enable notifications for private messages. Enable notifications for private messages. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Improve Form accessibility. Improve Form accessibility. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Enable Chinese locales zh-Hant zh-Hans. Enable Chinese locales zh-Hant zh-Hans. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Add locale alias system for localization. Add locale alias system for localization. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Improve Contacts page UI and functionality. Improve Contacts page UI and functionality. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Improve crowdfunding banner UI and logic. Improve crowdfunding banner UI and logic. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Dependency | Medium |
Upgrade chainpad-server to 5.3.0. Upgrade chainpad-server to 5.3.0. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Set bearer secret in environment variable. Set bearer secret in environment variable. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Initialize Diagram in read-only mode until ready. Initialize Diagram in read-only mode until ready. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Fix Table of contents not clickable read-only. Fix Table of contents not clickable read-only. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Check for other users before OnlyOffice upload. Check for other users before OnlyOffice upload. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Fix paragraph selection in richtext mobile. Fix paragraph selection in richtext mobile. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Enforce immediate access-list lockout prevent stale visibility. Enforce immediate access-list lockout prevent stale visibility. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Bugfix | Medium |
Remove kanban tags when board deleted. Remove kanban tags when board deleted. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Bugfix | Medium |
Update status for trashed OnlyOffice documents. Update status for trashed OnlyOffice documents. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Bugfix | Medium |
Fix app icons spacing Drive context menu. Fix app icons spacing Drive context menu. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Bugfix | Medium |
Fix sidebar buttons text overflow icon shrinking. Fix sidebar buttons text overflow icon shrinking. Source: llm_adapter@2026-05-21 Confidence: low |
— |
Full changelog
Goals
This release introduces an updated version of the Diagram app, now powered by Drawio 29. The app now defaults to the "sketch" theme, a simple infinite canvas suited to many uses from mind-mapping to freehand drawing. We introduce a theme switcher so that everyone can choose the right level of complexity for their needs. This release also comes with lots of fixes and improvements across CryptPad.
Features
- Upgrade Diagram app to Drawio 29.6.7 22fe846
- Button to switch diagram mode #2192
- Notifications for private messages #2133
Improvements
- Improve Form accessibility #2260
- Enable zh-Hant/zh-Hans locales (#2237) and add alias system for locales #2254 by @toomore
- Improve crowdfunding banner UI and show logic #2242
- Contacts page improvements #2219
Fixes
- fix: set bearer secret in env #2268 by @ebuildy
- Diagram initialized in read-only mode until document is ready #2238
- Fix #2216: Table of contents not clickable in read-only mode #2229 by @sliortega295-ops
- Enforce immediate access-list lockout and prevent stale content visibility on refresh #2226
- Fix app icons and spacing in Drive "Open in" context menu #2213
- Fix leftside sidebar buttons' text overflow and prevent icon shrinking #2212
- Fix paragraph selection in richtext for mobile #2208
- Remove kanban tags when board is deleted #2188
- Check for other users before OnlyOffice upload #2228
- Update status for trashed OnlyOffice documents #2183
Dependencies
- Upgrades
- chainpad-server: from ^5.2.4 to ^5.3.0
- drawio-npm: from 21.8.2+6 to 29.6.7+3
Upgrade notes
SSO plugin
If your instance relies on the SSO plugin for authentication, please upgrade the plugin to 0.5.0 as part of this upgrade.
CryptPad
If you are upgrading from a version older than 2026.2.2 please read the upgrade notes of all versions between yours and 2026.5.0 to avoid configuration issues.
To upgrade:
- Stop your server
- Get the latest code with git
git fetch --depth 1 origin tag 2026.5.0
git checkout 2026.5.0
npm ci
npm run install:components
./install-onlyoffice.sh
- Restart your server
- Review your instance's checkup page to ensure that you are passing all tests
Contributors
Community: @toomore @sliortega295-ops @ebuildy
CryptPad team: @AAAMON @Chouhartem @dariiing @davidbenque @DianaXWiki @wginolas @yflory @zuzanna-maria
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]