Skip to content

Career Ops UI

v1.117.1 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 20d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

airbnb-style ashby ats career-ops claude-code cv
+11 more
express greenhouse-api hh-ru job-application job-search lever local-first no-telemetry resume self-hosted sse

Summary

AI summary

Hardened shell‑out endpoints with per‑IP rate limiting and fully sanitized Add‑to‑CV URL extraction.

Full changelog

[1.117.1] — 2026-07-06

Hardening follow-up to v1.117.0 (CodeQL triage). The three shell-out endpoints (GET /api/followup, POST /api/followup/seed, GET /api/stats/patterns) now carry the shared per-IP rate limiter (they spawn a child process per request; no-op on loopback). The Add-to-CV URL text extraction strips tags to a fixed point and then removes every remaining </> outright — a provably complete sanitization for LLM-prompt text. No behavior change for valid input.

New: none.

Security Fixes

  • Added shared per‑IP rate limiter to GET /api/followup, POST /api/followup/seed, and GET /api/stats/patterns endpoints.
  • Add-to-CV URL text extraction now fully strips HTML tags and all remaining whitespace for provable sanitization.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Career Ops UI

Get notified when new releases ship.

Sign up free

About Career Ops UI

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]