Skip to content

leantime

v3.9.4 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agile asana calendar clickup gantt jira
+13 more
kanban lean leantime notion php project-management projects retrospective scrum sql strategy timesheets trello

Affected surfaces

auth

Summary

AI summary

Updates Other Changes, Bug Fixes, and Version: 3.9.4 across a mixed release.

Changes in this release

Bugfix Medium

Fixes loading of "My Work" tickets across different projects.

Fixes loading of "My Work" tickets across different projects.

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Fixes Sanctum‑guard session store error Bearer -32001 on gated methods.

Fixes Sanctum‑guard session store error Bearer -32001 on gated methods.

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Secures the mark‑ticket‑done action against unauthorized access.

Secures the mark‑ticket‑done action against unauthorized access.

Source: llm_adapter@2026-06-14

Confidence: low

Full changelog

Version: 3.9.4

Bug Fixes

  • My Work Across Projects - Fixed an issue that prevented "My Work" from loading tickets across different projects, and exposed and secured the mark-ticket-done action (#3527)

What's Changed

Other Changes

  • fix(auth): Sanctum-guard session stores role name not raw int (fixes Bearer -32001 on all gated methods) by @marcelfolaron in https://github.com/Leantime/leantime/pull/3525
  • Release v3.9.3 by @marcelfolaron in https://github.com/Leantime/leantime/pull/3526
  • fix(tickets): unblock cross-project 'my work' reads + expose/secure markTicketDone by @marcelfolaron in https://github.com/Leantime/leantime/pull/3527
  • Release v3.9.4 by @marcelfolaron in https://github.com/Leantime/leantime/pull/3528

Full Changelog: https://github.com/Leantime/leantime/compare/v3.9.2...v3.9.4

Security Fixes

  • Secured the mark-ticket-done action against unauthorized access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track leantime

Get notified when new releases ship.

Sign up free

About leantime

Leantime is a goals focused project management system for non-project managers. Building with ADHD, Autism, and dyslexia in mind.

All releases →

Related context

Earlier breaking changes

  • v3.9.1 Retire legacy API REST controllers.

Beta — feedback welcome: [email protected]