Skip to content

habitica

v5.48.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 10d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

css express habitica html javascript mongodb
+3 more
nodejs vue vuejs

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 10d

The release updates API endpoints and client routing logic while changing CSP header handling to use express instead of helmet.

Why it matters: Security: Sets Content-Security-Policy headers via express (severity 90). Bugfix: Adjusts user task move route for Challenge tasks (severity 40).

Summary

AI summary

Updates API, @SabreCat, and Client across a mixed release.

Changes in this release

Security Critical

Sets Content-Security-Policy headers using express instead of helmet

Sets Content-Security-Policy headers using express instead of helmet

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Uses user task move route when rearranging Challenge tasks

Uses user task move route when rearranging Challenge tasks

Source: llm_adapter@2026-07-16

Confidence: high

Full changelog

API

  • Security: Set Content-Security-Policy headers within express instead of helmet (@SabreCat)
  • Chore: Locale files updated (@weblate contributors)

Client

  • Fix: Employ user task move route, not group, when rearranging Challenge tasks (@Hafizzle)

Repo

  • Docs: Add No-AI note (@SabreCat)

Security Fixes

  • API security improvement – CSP headers configured directly in express instead of relying on helmet

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track habitica

Get notified when new releases ship.

Sign up free

About habitica

A habit tracker app which treats your goals like a Role Playing Game.

All releases →

Related context

Beta — feedback welcome: [email protected]