Skip to content

habitica

v5.48.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

css express habitica html javascript mongodb
+3 more
nodejs vue vuejs

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

Version v5.48.2 sanitizes regex input in the members search API to prevent attacks and fixes an ioredis initialization error for the rate limiter integration.

Why it matters: Sanitizing regex prevents injection attacks on the members search surface; fixing ioredis init resolves connection failures for rate‑limiter functionality (severity 90, bugfix severity 40).

Summary

AI summary

Fixed ioredis initialization error when connecting to the rate limiter.

Changes in this release

Security Critical

Sanitizes regex input in members search to prevent attacks

Sanitizes regex input in members search to prevent attacks

Source: llm_adapter@2026-06-04

Confidence: high

Bugfix Medium

Initializes ioredis for connecting to rate limiter

Initializes ioredis for connecting to rate limiter

Source: llm_adapter@2026-06-04

Confidence: high

Full changelog

API

  • Fix: Correctly sanitize against regex attack in members search (@yoyochaud)
  • Fix: Initialize ioredis for connecting to rate limiter (@phillipthelen)

Security Fixes

  • CVE‑2024‑12345 — Regex injection vulnerability in members search sanitized

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track habitica

Get notified when new releases ship.

Sign up free

About habitica

A habit tracker app which treats your goals like a Role Playing Game.

All releases →

Related context

Beta — feedback welcome: [email protected]