Skip to content

emdash

[email protected] scope: emdash Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 19d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

astro cms emdash typescript

Affected surfaces

auth rbac

Summary

AI summary

Updates Patch Changes, https://github.com/emdash-cms/emdash/pull/1850, and https://github.com/khoinguyenpham04 across a mixed release.

Full changelog

Patch Changes

  • #1850 b92807f Thanks @khoinguyenpham04! - Fixes internal media usage repair so partial draft failures, concurrent content deletes, and fresher usage writes keep repair coverage non-complete without discarding valid indexed usage.

  • #1863 9e4701e Thanks @swissky! - Fixes a privilege escalation on private plugin API routes: an editor (or a cross-origin page) could invoke admin-only, state-changing plugin routes by sending them as GET or HEAD instead of POST, which bypassed the permission tier and CSRF check. Every private plugin route now requires plugins:manage and the CSRF header regardless of HTTP method.

  • Updated dependencies []:

Security Fixes

  • CVE‑2024‑XXXXX — Privilege escalation on private plugin API routes fixed; all such routes now require `plugins:manage` permission and CSRF header regardless of HTTP method.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track emdash

Get notified when new releases ship.

Sign up free

About emdash

All releases →

Related context

Earlier breaking changes

Beta — feedback welcome: [email protected]