This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+4 more
Affected surfaces
Summary
AI summaryBulk‑submitting links now blocks javascript: URLs to prevent injection attacks.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Disallows javascript: URLs in bulk link submissions Disallows javascript: URLs in bulk link submissions Source: llm_adapter@2026-05-25 Confidence: low |
— |
| Dependency | Medium |
Updated dependencies Updated dependencies Source: llm_adapter@2026-05-25 Confidence: low |
— |
Full changelog
- Security fixes:
- The bulk-submitting of links now properly disallows
javascript:in URLs
- The bulk-submitting of links now properly disallows
- Dependencies were updated
Security Fixes
- Bulk link submission disallows javascript: URLs, preventing injection attacks.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About LinkAce
LinkAce is a self-hosted archive to collect links of your favorite websites.
Beta — feedback welcome: [email protected]