This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
Summary
AI summaryUpdates Client, API, and @SabreCat across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Can now access Gem gifting via username lookup Can now access Gem gifting via username lookup Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Overhaul of HTML strings to use variable interpolation instead of hardcoding URLs Overhaul of HTML strings to use variable interpolation instead of hardcoding URLs Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Don't trigger "leaving Habitica" warning for mailto links Don't trigger "leaving Habitica" warning for mailto links Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
API
- Chore: Locale files updated (@weblate contributors)
Client
- Feature: Can now access Gem gifting via lookup of a username (@Hafizzle)
- Fix: Overhaul of HTML strings across site to avoid hardcoding URLs in translated text, preferring variable interpolation, for security and futureproofing (@SabreCat)
- Fix: Don't trip "leaving Habitica" external site warning for mailto links (@SabreCat)
Security Fixes
- Overhauled HTML strings to avoid hard‑coded URLs, mitigating potential injection risks
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]