This release includes 1 security fix for security teams reviewing exposed deployments.
Affected surfaces
ReleasePort's take
Moderate signalReleasePort Layer 1 version 2.4.1 patches a multi‑tenant authorization flaw that lets company owners view other companies' user accounts.
Why it matters: The fix addresses an authorization bypass (severity 90) affecting user management; operators should upgrade immediately to prevent cross‑company data exposure.
Summary
AI summarySecurity patch fixes multi-tenant authorization allowing company owners to access other companies' user accounts.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes multi-tenant authorization issue allowing company owner to access other companies' user accounts. Fixes multi-tenant authorization issue allowing company owner to access other companies' user accounts. Source: llm_adapter@2026-06-14 Confidence: low |
— |
| Security | High |
Fixes a multi-tenant authorization issue in user management. Fixes a multi-tenant authorization issue in user management. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
Full changelog
Security patch for the 2.x line.
Fixes a multi-tenant authorization issue in user management where a company owner could access user accounts belonging to another company. All self-hosted 2.x installs should update.
Docker: invoiceshelf/invoiceshelf:2.4.1 (also :latest, :2, :2.4).
Security Fixes
- Fixes multi‑tenant authorization issue where a company owner could access user accounts of another company
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]