Skip to content

Career Ops UI

v1.58.4 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

airbnb-style ashby ats career-ops claude-code cv
+11 more
express greenhouse-api hh-ru job-application job-search lever local-first no-telemetry resume self-hosted sse

Affected surfaces

auth rce_ssrf

Summary

AI summary

Emit Content‑Security‑Policy on every response, fixing missing CSP for loopback traffic.

Full changelog

[1.58.4] — 2026-05-19

fix(security): NEW-1 — emit Content-Security-Policy on every response (was loopback-gated). Before v1.58.4 the CSP header was layered on only when isPubliclyExposed() was true (HOST bound beyond loopback); over 127.0.0.1 both / and /api/health returned no CSP, leaving UI.md()'s escape-first contract as the only XSS defence. The v1.58.3 MASTER regression (§5) flagged this as a stop-ship invariant gap. CSP is now unconditional and identical on every response regardless of bind address: default-src 'self'; script-src 'self'; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self'. script-src never allows 'unsafe-inline'/'unsafe-eval'. The directive set is unchanged from the prior exposed-only policy (already SPA-correct — Google Fonts allowlisted for Inter), so no visual or functional regression. tests/security-headers.test.mjs was rewritten to lock CSP-present-on-loopback; a Playwright route-walk (en/ru/ja/zh-TW × 7 routes) asserts 0 CSP violations. 900 unit · Playwright 58→59 · e2e 20/20+23/23. Next fix-prompt items (NEW-3, BUG-008-tb, NEW-2, M-1…) ship as subsequent one-fix releases per project doctrine. See qa/v158-regression/FIX-PROMPT-v1.58.4_and_beyond.md. (NEW-1)


Security Fixes

  • NEW-1 — Emit Content‑Security‑Policy on every response (previously omitted for loopback traffic).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Career Ops UI

Get notified when new releases ship.

Sign up free

About Career Ops UI

All releases →

Related context

Beta — feedback welcome: [email protected]