Skip to content

ideon

v0.9.4 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 23d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

brainstorming collaboration idea-management knowledge-base mental-space pkm
+5 more
productivity project-management visual-thinking visual-workspace whiteboard

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Fixed a privilege escalation vulnerability allowing read‑only collaborators to write/delete projects, and fixed an SSRF bypass in the image proxy for IPv4‑mapped IPv6 addresses.

Full changelog

Security

  • Fixed a privilege escalation vulnerability (GHSA-v3qr-4v8m-29rh) where a read-only collaborator could perform write and delete operations on a project, including wiping and replacing the entire canvas. Reported by @tonghuaroot.
  • Fixed an SSRF bypass (GHSA-cvcr-fcf6-366r) in the image proxy where IPv4-mapped IPv6 addresses (e.g. [::ffff:7f00:1]) could bypass the private IP blocklist and reach internal services. Reported by @tonghuaroot.

Security Fixes

  • GHSA-v3qr-4v8m-29rh — Fixed privilege escalation allowing read‑only collaborators to write and delete project data.
  • GHSA-cvcr-fcf6-366r — Fixed SSRF bypass in image proxy for IPv4‑mapped IPv6 addresses.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track ideon

Get notified when new releases ship.

Sign up free

About ideon

Your project is scattered across too many tools. Map the chaos on an infinite canvas where notes, files, TO-DOs (and more!) finally live together.

All releases →

Related context

Beta — feedback welcome: [email protected]