This release includes 1 security fix for security teams reviewing exposed deployments.
Published 4d
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
experience-management
form
forms
nextjs
react
reactjs
+10 more
survey
survey-analysis
survey-data
survey-form
surveys
tailwindcss
turborepo
typeform
typescript
xm
Affected surfaces
deps
Summary
AI summaryFixes enforce organization/workspace scoping and patches a decompression denial‑of‑service vulnerability.
Full changelog
What's Changed
- fix: enforce organization/workspace scoping across API keys, surveys, quotas, and integrations (ENG-1749) (backport to release/5.2) by @xernobyl in https://github.com/formbricks/formbricks/pull/8598
- fix: bump tar to 7.5.19 to patch decompression DoS (backport #8604 to release/5.2) by @Dhruwang in https://github.com/formbricks/formbricks/pull/8607
Full Changelog: https://github.com/formbricks/formbricks/compare/5.2.0...5.2.1
Security Fixes
- CVE‑2024‑XXXXX — decompression DoS in tar patched by bumping to 7.5.19
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]