Skip to content

kaneo

v2.9.2 Security

This release includes 13 security fixes for security teams reviewing exposed deployments.

Published 10d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 13 known CVEs

Topics

hono issue-management issue-tracker jira-alternative kanban linear-alternative
+4 more
project-management react self-hosted typescript

Affected surfaces

auth rbac

Summary

AI summary

Updates auth, api, and gitea across a mixed release.

Changes in this release

Feature Low

standardize avatar fallback initials

standardize avatar fallback initials

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix High

protect invitation acceptance from unverified accounts

protect invitation acceptance from unverified accounts

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix High

require verified email for account linking

require verified email for account linking

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Medium

reject active embed URL schemes in editor

reject active embed URL schemes in editor

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

prevent active content execution in assets

prevent active content execution in assets

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

enforce scoped API key permissions

enforce scoped API key permissions

Source: llm_adapter@2026-07-16

Confidence: low

Bugfix Medium

enforce disabled local login

enforce disabled local login

Source: llm_adapter@2026-07-16

Confidence: low

Bugfix Medium

restrict webhook secret access for Gitea integration

restrict webhook secret access for Gitea integration

Source: llm_adapter@2026-07-16

Confidence: low

Bugfix Medium

bind Gitea webhooks to signed integration

bind Gitea webhooks to signed integration

Source: llm_adapter@2026-07-16

Confidence: low

Bugfix Medium

require explicit OAuth consent for MCP

require explicit OAuth consent for MCP

Source: llm_adapter@2026-07-16

Confidence: low

Bugfix Medium

enforce task workspace boundary for labels

enforce task workspace boundary for labels

Source: llm_adapter@2026-07-16

Confidence: low

Bugfix Medium

validate registered redirect URIs for MCP

validate registered redirect URIs for MCP

Source: llm_adapter@2026-07-16

Confidence: low

Bugfix Medium

prevent cross-workspace moves in tasks

prevent cross-workspace moves in tasks

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Medium

prevent cross-workspace relations in tasks

prevent cross-workspace relations in tasks

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Medium

restore guest sign-in access

restore guest sign-in access

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

unify API and activity storage for comments

unify API and activity storage for comments

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Full changelog

What's Changed

  • fix(api): enforce scoped API key permissions by @tinsever in https://github.com/usekaneo/kaneo/pull/1374
  • fix(auth): enforce disabled local login by @tinsever in https://github.com/usekaneo/kaneo/pull/1375
  • fix(editor): reject active embed URL schemes by @tinsever in https://github.com/usekaneo/kaneo/pull/1376
  • fix(gitea): restrict webhook secret access by @tinsever in https://github.com/usekaneo/kaneo/pull/1377
  • fix(gitea): bind webhooks to signed integration by @tinsever in https://github.com/usekaneo/kaneo/pull/1378
  • fix(mcp): require explicit OAuth consent by @tinsever in https://github.com/usekaneo/kaneo/pull/1372
  • fix(assets): prevent active content execution by @tinsever in https://github.com/usekaneo/kaneo/pull/1373
  • fix(labels): enforce task workspace boundary by @tinsever in https://github.com/usekaneo/kaneo/pull/1380
  • fix(mcp): validate registered redirect URIs by @tinsever in https://github.com/usekaneo/kaneo/pull/1381
  • docs(security): remove public default MinIO credentials by @tinsever in https://github.com/usekaneo/kaneo/pull/1382
  • fix(api): prioritize project workspace lookup by @tinsever in https://github.com/usekaneo/kaneo/pull/1383
  • fix(tasks): prevent cross-workspace moves by @tinsever in https://github.com/usekaneo/kaneo/pull/1384
  • fix(tasks): prevent cross-workspace relations by @tinsever in https://github.com/usekaneo/kaneo/pull/1385
  • fix(auth): protect invitation acceptance from unverified accounts by @tinsever in https://github.com/usekaneo/kaneo/pull/1386
  • fix(auth): require verified email for account linking by @tinsever in https://github.com/usekaneo/kaneo/pull/1387
  • fix(comments): unify API and activity storage by @tinsever in https://github.com/usekaneo/kaneo/pull/1389
  • fix(auth): restore guest sign-in access by @tinsever in https://github.com/usekaneo/kaneo/pull/1391
  • feat: standardize avatar fallback initials by @yigit-serin in https://github.com/usekaneo/kaneo/pull/1401

New Contributors

  • @yigit-serin made their first contribution in https://github.com/usekaneo/kaneo/pull/1401

Full Changelog: https://github.com/usekaneo/kaneo/compare/v2.9.1...v2.9.2

Security Fixes

  • fix(api): enforce scoped API key permissions
  • fix(auth): enforce disabled local login
  • fix(gitea): restrict webhook secret access
  • fix(gitea): bind webhooks to signed integration
  • fix(mcp): require explicit OAuth consent
  • fix(assets): prevent active content execution
  • fix(labels): enforce task workspace boundary
  • fix(mcp): validate registered redirect URIs
  • docs(security): remove public default MinIO credentials
  • fix(auth): protect invitation acceptance from unverified accounts
  • fix(auth): require verified email for account linking
  • fix(comments): unify API and activity storage
  • fix(auth): restore guest sign-in access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kaneo

Get notified when new releases ship.

Sign up free

About kaneo

All you need. Nothing you don't. Open source project management that works for you, not against you.

All releases →

Related context

Beta — feedback welcome: [email protected]