This release includes 1 security fix for security teams reviewing exposed deployments.
Published 29d
Media Servers
✓ No known CVEs patched
This release patches 1 known CVE
Topics
arr
imagemagick
posters
Affected surfaces
deps
Summary
AI summaryUpdates New Features, Improvements & Refactoring, and Bug Fixes across a mixed release.
Full changelog
Security
- Frontend Dependency Update: Upgraded
@babel/coreto^7.29.7to patch a known arbitrary file read vulnerability, resolving a Dependabot security alert (CVE-2026-49356).
New Features
- Blueprints UI & Presets: Easily apply pre-defined configurations to achieve specific visual styles in a single click (e.g., Minimalist, Clearlogo, Flat White Logo, Resolution Overlays).
- Custom Blueprint Builder: Mix and match specific overlays, test them with a live bounding-box preview, and build your own custom layout right from the UI.
- Config Import/Export: Easily share your custom blueprints with the community or back up your configurations using the new Import/Export APIs.
Improvements & Refactoring
- Jellyfin Compatibility: Pinned Jellyfin dependencies (
Jellyfin.ControllerandJellyfin.Model) to 10.11.0 to ensure stable API communication. - Documentation: Added a new comprehensive Blueprints & Recipes guide covering multi-server syncs, minimalist posters, and advanced setups.
Bug Fixes
- Artwork Uploads: Fixed an issue with existing asset uploads by properly utilizing the global
seasonIdwhen pushing artwork to secondary media servers. - Preview Text Scaling: Fixed container queries and text scaling bugs in the WebUI preview renders.
Full Changelog: https://github.com/fscorrupt/posterizarr/compare/2.2.51...2.2.52
Security Fixes
- CVE-2026-49356 — Upgraded @babel/core to ^7.29.7 to patch arbitrary file read vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]