This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 1mo
File Storage & Sync
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
file-browser
file-manager
file-sharing
go
material-design
self-hosted
+1 more
vue
Affected surfaces
auth
rce_ssrf
Summary
AI summaryShare module fixes GHSA-pp88-jhwj-5qh5 and GHSA-833g-cqhp-h72j security issues; additional auth, raw, path, admin share, and subtitle improvements.
Full changelog
Changelog
- d76b7d161099853f17e71b1327ce4545a30c27a2 chore(release): 2.63.17
- f30fca636c1af9ef401e9a82ff60391cb3db97e1 fix(share): delete exact directory share on trailing-slash delete (GHSA-pp88-jhwj-5qh5)
- ec130546713c44cd24556907552ac554c7f809c9 fix(share): stop exposing password hash and bypass token in share API (GHSA-833g-cqhp-h72j)
- 883a36f02fcb69566a8628cb47f18fdc73348387 fix(auth): reject signup when normalized home dir collides (GHSA-7rc3-g7h6-22m7)
- 8503ba61ff51d48a7313896483d130eb6a5abfe0 fix(raw): neutralize backslashes in archive entry names (GHSA-83xp-526h-j3ww)
- 1fb05d65de98f8dc341409f40d382297ca75bcf0 docs,cmd: warn about broad scope for self-signup users (GHSA-6759-996p-gpj6)
- 2472fbcd30502606feb11fbc8b8dc4f3803e6641 fix: normalize recursive listing paths to forward slashes (#6003)
- 43a404ca69bf25553bfbbb2b446f0f53077c6302 fix: match admin share paths by owner scope (#5992)
- d9cf2f0100d2c4892cad8e339eacca96df1aa5b6 fix: preserve SRT subtitle line breaks (#6002)
- 6209f8fddd0f279b4d57571c0d5bb114affc1942 chore: update translations (#5990)
Security Fixes
- GHSA-pp88-jhwj-5qh5 — delete exact directory share on trailing-slash delete prevents unintended data removal
- GHSA-833g-cqhp-h72j — stop exposing password hash and bypass token in share API eliminates credential leakage
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]