This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+9 more
ReleasePort's take
Moderate signalVersion 2.59.0 resolves a high‑severity security issue reported by @shafiqaimanx.
Why it matters: The release patches a high‑severity (severity 90) security flaw; operators should upgrade immediately to mitigate risk.
Summary
AI summaryFix for a high‑severity security issue.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes a high severity security issue reported by @shafiqaimanx Fixes a high severity security issue reported by @shafiqaimanx Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Low |
Adds "user" filter to invoice archive Adds "user" filter to invoice archive Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Low |
Allows using forms and modals without padding Allows using forms and modals without padding Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Low |
Writes log message for failed image downloads (invoice/export templates) Writes log message for failed image downloads (invoice/export templates) Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Feature | Low |
Adds `user.account` and `entry.user_account` invoice template variables Adds `user.account` and `entry.user_account` invoice template variables Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Feature | Low |
Enables wizard extension by plugins Enables wizard extension by plugins Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes duplicate number generation on subsequent calls in one transaction for customer/project/activity Fixes duplicate number generation on subsequent calls in one transaction for customer/project/activity Source: llm_adapter@2026-06-06 Confidence: low |
— |
| Bugfix | Low |
Fixes JS issue for forms without events Fixes JS issue for forms without events Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Low |
Fixes adding an empty space in delete modals Fixes adding an empty space in delete modals Source: llm_adapter@2026-06-06 Confidence: low |
— |
| Bugfix | Low |
Removes extra space in delete modals UI Removes extra space in delete modals UI Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
Full changelog
Compatible with PHP 8.2 to 8.5
- Write log message for failed image downloads (invoice / export templates) (#5957)
- Add
user.accountandentry.user_accountas invoice template variables (#5957) - Fix number generator created duplicates on subsequent calls in one transaction for customer/project/activity (#5957)
- Allow wizard to be extended by plugins (see docs) (#5957)
- Added "user" as new filter for the invoice archive (#5957)
- JS fix for forms without events (#5957)
- Allow to use forms and modals without padding (#5957)
- Translations update from Hosted Weblate (#5954) (#5967)
- Fix adding an empty space in the delete modals (#5962)
Security
- This release contains a fix for a high severity security issue reported by @shafiqaimanx
You can read more about all published vulnerabilities here or grab a RSS feed to get notified about new published advisories.
Involved in this release: @cheriimoya and @kevinpapst and @shafiqaimanx
Security Fixes
- High‑severity security issue fixed (reported by @shafiqaimanx)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kimai
Kimai is the #1 open-source time-tracking application. From freelancers to companies and organisations - everyone can manage timesheets, generate reports, create invoices and so much more... Web-based multi-user application, available as On-Premise or SaaS version: https://www.kimai.org
Beta — feedback welcome: [email protected]