Skip to content

hedgedoc

v1.11.0 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

codimd collaboration diagrams editor hackmd hedgedoc
+3 more
markdown notes real-time

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Updates Enhancements, Important notices, and https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-6c2w-8w96-3pcv across a mixed release.

Full changelog

Security fixes

This release contains four security fixes:

Thanks to Chandler Johnson, taylorodell and alanturing881 for reporting!

Important notices

  • When using Cloudflare in front of HedgeDoc, you should set rateLimitUsingCloudflare in the config.json or CMD_RATE_LIMIT_USING_CLOUDFLARE as environment variable to true.

Enhancements

  • Added a warning page when clicking external links
  • Improve the config.json.example file, which is used by bin/setup
  • Allow configuration of login / signup rate-limits
  • Allow configuration of Cloudflare usage in regards of rate-limits
  • Several improvements in the documentation at https://docs.hedgedoc.org

Security Fixes

  • GHSA-6c2w-8w96-3pcv — possible HTML injection via email address localpart
  • GHSA-qj78-mjch-wwrv — possible Denial-of-Service from YAML frontmatter parsing
  • GHSA-8v9p-5j95-826j — possible CSRF attack vector in GitHub Gist export
  • GHSA-2f9f-w8xq-276v — rate‑limit bypass abusing CF-Connecting-IP header

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track hedgedoc

Get notified when new releases ship.

Sign up free

About hedgedoc

HedgeDoc - Ideas grow better together

All releases →

Related context

Beta — feedback welcome: [email protected]