This release includes 13 security fixes for security teams reviewing exposed deployments.
Topics
+4 more
Affected surfaces
Summary
AI summaryUpdates auth, api, and gitea across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
standardize avatar fallback initials standardize avatar fallback initials Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | High |
protect invitation acceptance from unverified accounts protect invitation acceptance from unverified accounts Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | High |
require verified email for account linking require verified email for account linking Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Medium |
reject active embed URL schemes in editor reject active embed URL schemes in editor Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
prevent active content execution in assets prevent active content execution in assets Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
enforce scoped API key permissions enforce scoped API key permissions Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
enforce disabled local login enforce disabled local login Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
restrict webhook secret access for Gitea integration restrict webhook secret access for Gitea integration Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
bind Gitea webhooks to signed integration bind Gitea webhooks to signed integration Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
require explicit OAuth consent for MCP require explicit OAuth consent for MCP Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
enforce task workspace boundary for labels enforce task workspace boundary for labels Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
validate registered redirect URIs for MCP validate registered redirect URIs for MCP Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
prevent cross-workspace moves in tasks prevent cross-workspace moves in tasks Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Medium |
prevent cross-workspace relations in tasks prevent cross-workspace relations in tasks Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Medium |
restore guest sign-in access restore guest sign-in access Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Low |
unify API and activity storage for comments unify API and activity storage for comments Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
Full changelog
What's Changed
- fix(api): enforce scoped API key permissions by @tinsever in https://github.com/usekaneo/kaneo/pull/1374
- fix(auth): enforce disabled local login by @tinsever in https://github.com/usekaneo/kaneo/pull/1375
- fix(editor): reject active embed URL schemes by @tinsever in https://github.com/usekaneo/kaneo/pull/1376
- fix(gitea): restrict webhook secret access by @tinsever in https://github.com/usekaneo/kaneo/pull/1377
- fix(gitea): bind webhooks to signed integration by @tinsever in https://github.com/usekaneo/kaneo/pull/1378
- fix(mcp): require explicit OAuth consent by @tinsever in https://github.com/usekaneo/kaneo/pull/1372
- fix(assets): prevent active content execution by @tinsever in https://github.com/usekaneo/kaneo/pull/1373
- fix(labels): enforce task workspace boundary by @tinsever in https://github.com/usekaneo/kaneo/pull/1380
- fix(mcp): validate registered redirect URIs by @tinsever in https://github.com/usekaneo/kaneo/pull/1381
- docs(security): remove public default MinIO credentials by @tinsever in https://github.com/usekaneo/kaneo/pull/1382
- fix(api): prioritize project workspace lookup by @tinsever in https://github.com/usekaneo/kaneo/pull/1383
- fix(tasks): prevent cross-workspace moves by @tinsever in https://github.com/usekaneo/kaneo/pull/1384
- fix(tasks): prevent cross-workspace relations by @tinsever in https://github.com/usekaneo/kaneo/pull/1385
- fix(auth): protect invitation acceptance from unverified accounts by @tinsever in https://github.com/usekaneo/kaneo/pull/1386
- fix(auth): require verified email for account linking by @tinsever in https://github.com/usekaneo/kaneo/pull/1387
- fix(comments): unify API and activity storage by @tinsever in https://github.com/usekaneo/kaneo/pull/1389
- fix(auth): restore guest sign-in access by @tinsever in https://github.com/usekaneo/kaneo/pull/1391
- feat: standardize avatar fallback initials by @yigit-serin in https://github.com/usekaneo/kaneo/pull/1401
New Contributors
- @yigit-serin made their first contribution in https://github.com/usekaneo/kaneo/pull/1401
Full Changelog: https://github.com/usekaneo/kaneo/compare/v2.9.1...v2.9.2
Security Fixes
- fix(api): enforce scoped API key permissions
- fix(auth): enforce disabled local login
- fix(gitea): restrict webhook secret access
- fix(gitea): bind webhooks to signed integration
- fix(mcp): require explicit OAuth consent
- fix(assets): prevent active content execution
- fix(labels): enforce task workspace boundary
- fix(mcp): validate registered redirect URIs
- docs(security): remove public default MinIO credentials
- fix(auth): protect invitation acceptance from unverified accounts
- fix(auth): require verified email for account linking
- fix(comments): unify API and activity storage
- fix(auth): restore guest sign-in access
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kaneo
All you need. Nothing you don't. Open source project management that works for you, not against you.
Related context
Related tools
Beta — feedback welcome: [email protected]