This release includes 1 security fix for security teams reviewing exposed deployments.
Published 16d
Media Servers
✓ No known CVEs patched
This release patches 1 known CVE
Topics
audio
laravel
music
music-player
streaming
vue
Affected surfaces
rce_ssrf
Summary
AI summaryFixed URL validation during podcast sync, playback, and radio AI tool usage.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Validate URLs at podcast sync, playback, and radio AI tool. Validate URLs at podcast sync, playback, and radio AI tool. Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
Full changelog
What's Changed
- docs: add upgrade guide and simplify FrankenPHP install pages by @phanan in https://github.com/koel/koel/pull/2484
- fix: validate URLs at podcast sync, playback, and radio AI tool (GHSA-7j2f-6h2r-6cqc) by @phanan in https://github.com/koel/koel/pull/2485
Full Changelog: https://github.com/koel/koel/compare/v9.3.3...v9.3.4
Security Fixes
- GHSA-7j2f-6h2r-6cqc — validates URLs at podcast sync, playback, and radio AI tool to prevent misuse
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]