This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+11 more
Summary
AI summaryHardened shell‑out endpoints with per‑IP rate limiting and fully sanitized Add‑to‑CV URL extraction.
Full changelog
[1.117.1] — 2026-07-06
Hardening follow-up to v1.117.0 (CodeQL triage). The three shell-out endpoints (GET /api/followup, POST /api/followup/seed, GET /api/stats/patterns) now carry the shared per-IP rate limiter (they spawn a child process per request; no-op on loopback). The Add-to-CV URL text extraction strips tags to a fixed point and then removes every remaining </> outright — a provably complete sanitization for LLM-prompt text. No behavior change for valid input.
New: none.
Security Fixes
- Added shared per‑IP rate limiter to GET /api/followup, POST /api/followup/seed, and GET /api/stats/patterns endpoints.
- Add-to-CV URL text extraction now fully strips HTML tags and all remaining whitespace for provable sanitization.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Career Ops UI
All releases →Beta — feedback welcome: [email protected]