This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Moderate signalVersion 1.0.8.5 removes the editor/* permission for the editor role and adds input‑sanitization fixes.
Why it matters: Removal of editor/* triggers configuration migration; sanitization patches block XSS with severity 90.
Summary
AI summaryRemoved the editor/* permission for the editor role, requiring migration of role configurations.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Sanitize save global file, removed editor/* permission for editor role Sanitize save global file, removed editor/* permission for editor role Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Security | Critical |
Sanitize theme name to prevent injection attacks Sanitize theme name to prevent injection attacks Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Security | Critical |
Added sanitize to user bio on profile save; fixed sanitizeHTML to block XSS variants Added sanitize to user bio on profile save; fixed sanitizeHTML to block XSS variants Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Feature | Low |
Introduced field templates for easier form creation Introduced field templates for easier form creation Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Bugfix | Medium |
Validate URL by checking host IP address to avoid private‑network redirects Validate URL by checking host IP address to avoid private‑network redirects Source: llm_adapter@2026-06-07 Confidence: low |
— |
Full changelog
- Sanitize save global file, removed editor/* permission for editor role, reported by @m1n9yu3 https://github.com/givanz/Vvveb/commit/c8fef41ad8651d348050c513451755ab8882b97e
- Sanitize theme name, reported by @geo-chen https://github.com/givanz/Vvveb/commit/1d76ad52402beeed623a7e386c6796126689a746
- Added sanitize to user bio on profile save, fixed sanitizeHTML to prevent more XSS variants, reported by @JosanGeorge https://github.com/givanz/Vvveb/commit/20a01ef08559ffdc97205edeecde86c8ea27e567
- Check host ip address for validateUrl to avoid ip redirects to private network, reported by @elvinsuleymanov https://github.com/givanz/Vvveb/commit/bd280f5ce136f6da22c873fb1eea9cad8741e623
- Field templates https://github.com/givanz/Vvveb/commit/57a342b8c96872e084fef7931783243dc74438b1
Breaking Changes
- Removed editor/* permission for the editor role
Security Fixes
- Fixed sanitizeHTML to prevent additional XSS variants
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Vvveb CMS
Powerful and easy to use CMS to build websites, blogs or e-commerce stores.
Beta — feedback welcome: [email protected]