Skip to content

MailFlow

v1.7.0 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 1mo Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

email emailclient unifiedinbox webmail

Affected surfaces

deps

Summary

AI summary

Upgraded dependencies nodemailer, ws, and express to resolve multiple high/moderate security vulnerabilities.

Full changelog

Features

  • Run inbox rules on existing messages — A new "Run rules on inbox" button in the Admin Panel applies your inbox rules retroactively to all existing messages, not just newly arrived ones. (#155)
  • Arrow key navigation in message list — Use ↑/↓ to move between messages; the selected row scrolls into view automatically. (#154)
  • Persistent compose window size — The compose window remembers the size you dragged it to across sessions. (#153)
  • Auto-save compose to Drafts — Closing the compose window without sending saves the draft to your Drafts folder on the server so it's accessible from any client. (#152)
  • Send warnings for empty subject and forgotten attachments — MailFlow warns you before sending if the subject line is blank or if the message body mentions an attachment but none is attached. (#151)

Fixes

  • Fixed thread rows staying bold after marking read in conversation view when no sub-messages were cached.
  • Fixed virtual folders stealing messages from real folders during IMAP sync. (#160)
  • Fixed draft messages not being permanently deleted from the message list, and a unique-key race condition when moving to trash. (#152)
  • Fixed inbox rules run timing out on large mailboxes — now paginates all inbox messages in batches of 500 instead of capping at 1,000. (#155)

Security

  • Upgraded nodemailer to 9.0.1, resolving four high/moderate CVEs (GHSA-268h-hp4c-crq3, GHSA-wqvq-jvpq-h66f, GHSA-r7g4-qg5f-qqm2, GHSA-p6gq-j5cr-w38f).
  • Upgraded ws to 8.21.0, resolving GHSA-96hv-2xvq-fx4p.
  • Upgraded express and qs to clear a moderate DoS CVE (GHSA-q8mj-m7cp-5q26).

Chores

  • ESLint now enforces a zero-warning ceiling (--max-warnings 0) in both backend and frontend CI.

Security Fixes

  • Upgraded nodemailer to 9.0.1 — resolves GHSA-268h-hp4c-crq3, GHSA-wqvq-jvpq-h66f, GHSA-r7g4-qg5f-qqm2, GHSA-p6gq-j5cr-w38f
  • Upgraded ws to 8.21.0 — resolves GHSA-96hv-2xvq-fx4p
  • Upgraded express and qs — clears moderate DoS CVE GHSA-q8mj-m7cp-5q26

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track MailFlow

Get notified when new releases ship.

Sign up free

About MailFlow

Unified webmail client

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]