Skip to content

InvoiceShelf

v2.4.0 Security

This release includes 7 security fixes for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 7 known CVEs

Affected surfaces

auth deps

Summary

AI summary

Updates Build & Tooling, Translations, and 2027-09-01 across a mixed release.

Full changelog

2.x is entering feature freeze

InvoiceShelf 2.4.0 marks the feature freeze for the 2.x line. New feature development now moves to the next-generation 3.x branch. From here, 2.x will receive security patches only, through September 1, 2027 (2027-09-01) — no new features, but it stays supported and safe to run. We recommend planning your upgrade to 3.x before then; the in-app updater path to 3.x is being prepared.

This release rolls up the final round of 2.x work: security hardening, dependency updates, groundwork for a clean v2 → v3 upgrade, a move to pnpm for the frontend toolchain, and a couple of contributor features.

Security

  • Enforce company scope on notes, estimate→invoice conversion, and user bulk-delete — GHSA-85wc, GHSA-j2vg, GHSA-wxrv (#661)
  • Harden public EmailLog token endpoints — GHSA-73q7 (#662)
  • Validate ORDER BY input on list endpoints — GHSA-cp8p (#663)
  • Restrict the Gotenberg renderer host to public addresses — GHSA-mfxg (#664)
  • Recompute document totals server-side so client-supplied totals aren't trusted — GHSA-8c69 (#665)
  • Update dependencies to patched versions (#674): laravel/framework (CVE-2026-48019), symfony/*, guzzlehttp/psr7, vite
  • Patch frontend dependencies — axios, vite, postcss, follow-redirects (#653)

Improvements

  • Add duplicate expense action (#617) — @mchev
  • Support 3-decimal tax percentages, e.g. 6.625% (#616) — @mchev
  • Updater: manifest-based stale-file cleanup + cache clearing, preparing a clean v2 → v3 in-app upgrade path (#659)

Build & Tooling

  • Migrate the frontend toolchain to pnpm and pin a stable Vite build (#666, #674)

Translations

  • New Crowdin translation updates across many locales (#615)

ℹ️ The CSV export work (#649) was reverted before this release and is deferred.

Full Changelog: https://github.com/InvoiceShelf/InvoiceShelf/compare/2.3.3...2.4.0

Breaking Changes

  • All new feature development halted for 2.x; only security patches will be released through September 1 2027 (2027-09-01).

Security Fixes

  • GHSA-85wc — Enforce company scope on notes, estimate→invoice conversion, and user bulk-delete.
  • GHSA-j2vg — Harden public EmailLog token endpoints.
  • GHSA-wxrv — Validate `ORDER BY` input on list endpoints.
  • GHSA-mfxg — Restrict Gotenberg renderer host to public addresses.
  • GHSA-8c69 — Recompute document totals server‑side; do not trust client‑supplied totals.
  • CVE-2026-48019 (laravel/framework) patched via dependency update (#674).
  • Frontend dependencies (axios, vite, postcss, follow-redirects) updated to patched versions (#653).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track InvoiceShelf

Get notified when new releases ship.

Sign up free

About InvoiceShelf

Open Source Invoicing Solution for Individuals & Businesses

All releases →

Related context

Beta — feedback welcome: [email protected]