This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalReleasePort Layer 1 v3.0.1 fixes a high‑severity CodeQL path traversal vulnerability by improving font handler sanitization.
Why it matters: The update resolves a high‑severity (CVSS 90) CodeQL path traversal flaw affecting path sanitization and error handling in font handlers; deploy v3.0.1 to mitigate the risk.
Summary
AI summaryFixes high severity CodeQL path traversal warnings by enhancing font handler sanitization.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes high-severity CodeQL path traversal vulnerability. Fixes high-severity CodeQL path traversal vulnerability. Source: llm_adapter@2026-07-14 Confidence: high |
— |
Full changelog
What's Changed
- Hotfix: Address High Severity CodeQL Path Traversal Warnings by @fscorrupt in https://github.com/fscorrupt/posterizarr/pull/607
- Hotfix: Enhance path sanitization and error handling in font handlers by @fscorrupt in https://github.com/fscorrupt/posterizarr/pull/608
Full Changelog: https://github.com/fscorrupt/posterizarr/compare/3.0.0...3.0.1
Security Fixes
- Address high severity CodeQL path traversal warnings via enhanced sanitization in font handlers
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]