This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalUpdate the nginx runtime dependency to version 1.30.2 and upgrade DOMPurify to version 3.4.5.
Why it matters: The release mandates upgrading nginx to 1.30.2 and DOMPurify to 3.4.5; failure leaves known security vulnerabilities unmitigated.
Summary
AI summarySecurity patches including updates to nginx and DOMPurify.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Update nginx runtime dependency to version 1.30.2. Update nginx runtime dependency to version 1.30.2. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Security | High |
Upgrade DOMPurify library to version 3.4.5. Upgrade DOMPurify library to version 3.4.5. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Low |
Reply with HTTP status code 500 on initialization error. Reply with HTTP status code 500 on initialization error. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Fix nullable filter SQL precedence issue. Fix nullable filter SQL precedence issue. Source: llm_adapter@2026-06-06 Confidence: low |
— |
| Bugfix | Medium |
Escape metadata parsing errors before rendering custom fields. Escape metadata parsing errors before rendering custom fields. Source: llm_adapter@2026-06-06 Confidence: low |
— |
| Bugfix | Low |
Handle empty values for link-type extra fields in metadata parsing. Handle empty values for link-type extra fields in metadata parsing. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Low |
Preserve selected category when editing cat/status fields in malle. Preserve selected category when editing cat/status fields in malle. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Low |
Fix path issue for tinymce dark theme. Fix path issue for tinymce dark theme. Source: llm_adapter@2026-06-06 Confidence: high |
— |
Full changelog
This release contains security patches (nothing critical).
Full Changelog: https://github.com/elabftw/elabftw/compare/5.5.13...5.5.14
9204473c8 bug/minor: shorter scope for steps readOne() (#6908)
7379d34d8 bug/minor: shorter scope for request actions readOne() (#6911)
c42289117 bug/minor: metadata: handle empty values for link-type extra fields (#6888)
869f64d1c bug/medium: custom fields: escape metadata parsing errors before rendering (#6910)
f02b12de9 bug/minor:malle: preserve selected category when editing cat/status fields (#6900)
88a7ea055 bug/minor: tinymce dark: fix path (#6896)
c47a54602 feat: reply with status code 500 on init error (#6887)
8d468b443 5.5.14
cca1fba13 bug/medium: fix nullable filter SQL precedence (#6889)
0d8350c0b security: update nginx to 1.30.2
5af72bc5e security: update nginx to 1.30.1 (#6829)
679318157 security: upgrade DOMPurify to 3.4.5
Security Fixes
- Update nginx to version 1.30.2
- Upgrade DOMPurify to version 3.4.5
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About eLabFTW
Online lab notebook for research labs. Store experiments, use a database to find reagents or protocols, use trusted timestamping to legally timestamp an experiment, export as pdf or zip archive, share with collaborators….
Related context
Related tools
Beta — feedback welcome: [email protected]