Skip to content

hedgedoc

v1.11.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

codimd collaboration diagrams editor hackmd hedgedoc
+3 more
markdown notes real-time

Affected surfaces

rbac

Summary

AI summary

Updates Enhancements, Bugfixes, and Refactoring / Clean-up across a mixed release.

Full changelog

Security fixes

  • GHSA-93w7-49m2-cqwg reports possible corruption of permission values due to missing validation. This should not impact permission checks, except when the note owner intentionally set their note permission to something invalid.

Enhancements

  • Added external link warning setting (externalLinkWarning in config.json or CMD_EXTERNAL_LINK_WARNING) to disable the external link warning page entirely
  • Added external link whitelist setting (externalLinkWhitelist in config.json or CMD_EXTERNAL_LINK_WHITELIST) to skip warning page for certain domains
  • Added support for webp file uploads (for all backends except imgur, since that does not support these)

Bugfixes

  • Fixed external link warning for subpath instances
  • Restore native browser zoom-in keyboard shortcuts in the editor
  • Nested list items render properly again in the preview pane for slides

Refactoring / Clean-up

  • Removed the old Temp database object and related API endpoints. This was used by a very old way of migrating the history and is no longer needed.
  • Removed unused allowOrigin (environment variable CMD_ALLOW_ORIGIN) config option.
  • Removed unnecessary/duplicate entries in the XSS filtering whitelist

Contributors

Breaking Changes

  • Removed the old Temp database object and related API endpoints.
  • Removed unused `allowOrigin` (environment variable `CMD_ALLOW_ORIGIN`) config option.

Security Fixes

  • GHSA-93w7-49m2-cqwg – Fixed possible corruption of permission values due to missing validation.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track hedgedoc

Get notified when new releases ship.

Sign up free

About hedgedoc

HedgeDoc - Ideas grow better together

All releases →

Related context

Beta — feedback welcome: [email protected]