Skip to content

minthcm

v4.3.2 Security

This release patches 1 CVE for security teams tracking exposure across their dependency inventory.

1 patched CVE
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE CVE-2020-11023 EPSS 84%
1 CVEs patched

Topics

ai-agent hcm hr hrm human-capital human-capital-management
+13 more
human-capital-project human-resources leave-management mcp mcp-server offboarding onboarding recruitment self-hosted time-management time-managment workforce-management workplace

Affected surfaces

auth rbac deps rce_ssrf

ReleasePort's take

Moderate signal
editorial:auto 11d

Version 4.3.2 introduces a Content‑Security‑Policy header and patches multiple third‑party libraries, fixing several security vulnerabilities.

Why it matters: The release adds a CSP header (severity 90) and updates jQuery, YUI, FullCalendar, and jsTree to patch vulnerabilities (severity 85), directly reducing exposure for HTTP responses and bundled JS assets.

Summary

AI summary

Updates Bug Fixes, New Features, and Security Fixes across a mixed release.

Changes in this release

Security Critical

Introduced Content-Security-Policy header.

Introduced Content-Security-Policy header.

Source: llm_adapter@2026-07-15

Confidence: high

Security High

Updated jQuery, YUI, FullCalendar, jsTree to patch vulnerabilities.

Updated jQuery, YUI, FullCalendar, jsTree to patch vulnerabilities.

Source: llm_adapter@2026-07-15

Confidence: high

Security High

Fixed authenticated SQL injection in legacy V8 API filter handling.

Fixed authenticated SQL injection in legacy V8 API filter handling.

Source: llm_adapter@2026-07-15

Confidence: high

Security High

Sanitized Comments module description field to prevent stored XSS.

Sanitized Comments module description field to prevent stored XSS.

Source: llm_adapter@2026-07-15

Confidence: high

Security High

Added missing parent‑record ACL check on subpanel endpoint to prevent IDOR.

Added missing parent‑record ACL check on subpanel endpoint to prevent IDOR.

Source: llm_adapter@2026-07-15

Confidence: high

Security Medium

Fixed self‑XSS vulnerability in `login_language` parameter handling.

Fixed self‑XSS vulnerability in `login_language` parameter handling.

Source: llm_adapter@2026-07-15

Confidence: high

Security Medium

Restricted public access to markdown documentation files.

Restricted public access to markdown documentation files.

Source: llm_adapter@2026-07-15

Confidence: high

Security Medium

Prevented sensitive fields from being exposed via legacy V8 API.

Prevented sensitive fields from being exposed via legacy V8 API.

Source: llm_adapter@2026-07-15

Confidence: high

Security Medium

Restricted access to publicly reachable directories and files.

Restricted access to publicly reachable directories and files.

Source: llm_adapter@2026-07-15

Confidence: high

Breaking High

Removed legacy ESList module containing security issues; migrate to Vue frontend.

Removed legacy ESList module containing security issues; migrate to Vue frontend.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Added New Prompt Templates module with md-editor-v3.

Added New Prompt Templates module with md-editor-v3.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Added dedicated MintMCP login view for server authentication.

Added dedicated MintMCP login view for server authentication.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Implemented internal authorization handling for agent access to MCP tools.

Implemented internal authorization handling for agent access to MCP tools.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Extended MintMCP with documentation retrieval, report invocation, many‑to‑many relationships, MCP Apps support, and built‑in CRM tools with an interaction loop.

Extended MintMCP with documentation retrieval, report invocation, many‑to‑many relationships, MCP Apps support, and built‑in CRM tools with an interaction loop.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Added automated regression test suite for MintMCP tools.

Added automated regression test suite for MintMCP tools.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Added OpenID Connect (OIDC) authentication support and improved SSO to allow classic login/password alongside SSO.

Added OpenID Connect (OIDC) authentication support and improved SSO to allow classic login/password alongside SSO.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Added SAML authentication support to the modern API layer.

Added SAML authentication support to the modern API layer.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Enabled linking events to candidates.

Enabled linking events to candidates.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Allowed recurrence to repeat until a specific end date.

Allowed recurrence to repeat until a specific end date.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Displayed progress indicator while saving recurring records.

Displayed progress indicator while saving recurring records.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Added file attachment support on Candidate and Candidature records.

Added file attachment support on Candidate and Candidature records.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Performed various subpanel configuration improvements.

Performed various subpanel configuration improvements.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Showed image previews directly on record view for attached files.

Showed image previews directly on record view for attached files.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Updated "Recently viewed" list when a record view is opened.

Updated "Recently viewed" list when a record view is opened.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Automatically scrolled forms to the first invalid field on validation failure.

Automatically scrolled forms to the first invalid field on validation failure.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Enabled closing tasks directly from the dashlet.

Enabled closing tasks directly from the dashlet.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Added "select all" option on list view rows.

Added "select all" option on list view rows.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Introduced configurable operation modes for an instance.

Introduced configurable operation modes for an instance.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Improved keyboard navigation and focus handling across homepage, list views, forms, and general navigation (WCAG).

Improved keyboard navigation and focus handling across homepage, list views, forms, and general navigation (WCAG).

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Redirected to relevant screen when a notification is clicked.

Redirected to relevant screen when a notification is clicked.

Source: granite4.1:30b@2026-07-15-audit

Confidence: high

Feature Low

Enabled offboarding generation for Active, During Termination, and Terminated employee statuses.

Enabled offboarding generation for Active, During Termination, and Terminated employee statuses.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Feature Low

Added previously missing endpoints to the legacy V8 API.

Added previously missing endpoints to the legacy V8 API.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Full changelog

New Features

  • New Prompt Templates module — Added a new module for managing AI prompt templates, with an embedded md-editor-v3 editor.
  • Mint MCP — MCP login view — Added a dedicated login view for authenticating to the MintMCP server.
  • MintMCP — internal authorization for the Agent in MCP — Added internal authorization handling for agent access to MCP tools.
  • Mint MCP tooling expansion — Extended MintMCP with documentation retrieval, report invocation, many-to-many relationship handling, MCP Apps support, and built-in CRM tools with an agent–tool interaction loop.
  • Mint MCP — automated regression tests — Added an automated regression test suite for MCP tools.
  • OpenID Connect (OIDC) and SSO login support — Added OIDC authentication support and improved SSO login to allow logging in with a classic login/password alongside SSO.
  • SAML support in the new API — Added SAML authentication support to the modern API layer.
  • Events — support for candidates — Events can now be linked to candidates.
  • Recurrence until a given date — Added the ability to set recurrence to repeat until a specific date.
  • Progress bar during save with recurrence — Added a progress indicator while saving recurring records.
  • Adding files to Candidates and Candidatures — Added file attachment support on Candidate and Candidature records.
  • Subpanel modifications — Various subpanel configuration improvements.
  • Files — image preview on record view — Images attached to a record are now previewed directly on the record view.
  • Recently viewed — update on entering record view — The "Recently viewed" list now updates when a record view is opened.
  • Scroll to invalid field on validation — The form now automatically scrolls to the first field that fails validation.
  • Closing tasks from the dashlet — Tasks can now be closed directly from the dashlet.
  • List view — select all records — Added a "select all" option on list views.
  • Offboarding generation for more employee statuses — Offboarding can now be generated for employees with Active, During Termination, and Terminated statuses.
  • Missing API V8 endpoints — Added previously missing endpoints to the legacy V8 API.
  • Notifications — screen redirect — Clicking a notification now redirects to the relevant screen.
  • Instance operation modes — Added configurable operation modes for an instance.
  • WCAG keyboard accessibility — Improved keyboard navigation and focus handling across the homepage, list views, forms, and general navigation.

Security Fixes

  • Content-Security-Policy (CSP) — Introduced a Content-Security-Policy header.
  • jQuery, YUI, FullCalendar, jsTree updates — Updated bundled third-party JS libraries to patch known vulnerabilities.
  • Hiding fields in API V8 — Prevented sensitive fields from being exposed via the legacy V8 API.
  • Hiding markdown files — Restricted public access to markdown documentation files.
  • Self-XSS via login_language parameter — Fixed improper input handling in the login_language parameter that allowed self-XSS.
  • IDOR via subpanel endpoint — Added a missing parent-record ACL check on the subpanel endpoint that allowed cross-record data access.
  • Stored XSS in Comments module — Sanitized the description field before rendering via v-html in the Comments module.
  • Authenticated SQL Injection in Legacy V8 API — Fixed SQL injection in the legacy V8 API filter handling of in/not_in operators.
  • Publicly accessible directories and files — Restricted access to directories and files that should not be publicly reachable.
  • Removal of ESList — Removed the legacy ESList module, which contained a number of security issues, now superseded by the Vue frontend.

Bug Fixes

  • Installer fix via replacement — Fixed the installer by replacing the faulty component.
  • Broken logic on views — Fixed view logic that was not executing correctly.
  • Broken links in subpanels — Fixed non-clickable links inside subpanels.
  • "Forgot password?" screen not working — Fixed the forgot-password flow.
  • Elastic error when a record doesn't exist — Fixed an ElasticSearch error triggered by missing records.
  • Records not saving — Fixed an issue preventing record saves.
  • Candidates — Birthdate not required despite spec — Fixed field requirement mismatch on the Birthdate field.
  • Duplicate notifications (bell icon) — Fixed duplicate notification entries.
  • List view column headers in wrong language — Fixed incorrect language display for list view column headers.
  • Studio issues found during testing — Fixed several issues identified in Studio.
  • Entity generator randomly clearing entities — Fixed a bug in the entity generator that could clear unrelated entities.
  • Cannot create a record in Terms of Employment module — Fixed record creation failure.
  • Save notification not shown — Fixed missing confirmation notification on save.
  • Delegations / Costs — module errors — Fixed multiple errors in the Delegations/Costs module.
  • Work Time — module errors — Fixed multiple errors in the Work Schedules/Time module.
  • Cannot create a record in the Room module — Fixed a relation issue with the Office field preventing record creation.
  • Cannot create a record in Knowledge module (Error 500) — Fixed a server error preventing record creation.
  • Cannot create Training linked to an Employee — Fixed record creation from an Employee subpanel.
  • Minor bugs in Contracts and Terms of Employment — Fixed several minor bugs.
  • Field editing in Studio — Fixed field editing issues in Studio.
  • Autofill vs. labels on login screen — Fixed a conflict between browser autofill and floating labels on the login form.
  • API authentication error — Fixed an authentication error in the API.
  • Closing meetings from the dashlet — Fixed an issue preventing meetings from being closed via the dashlet.
  • Recurrence view fixes — Fixed issues in the recurrence view.
  • Search view filters not working correctly — Fixed filter behavior on the search view.
  • Cmd/Ctrl-click on logo doesn't open in a new tab — Fixed logo link behavior for modifier-key clicks.
  • Incorrect meeting participant search — Fixed search results for meeting participants.
  • View options — module order not saved in menu — Fixed menu module ordering not persisting.
  • Sorting error on Employees list — Fixed a crash when sorting the Employees list.
  • Regular users lack access to MintMCP tools — Fixed a permission issue blocking non-admin MCP tool access.
  • Ratings dashlet showing wrong status field — Fixed incorrect status display on the Ratings dashlet.
  • UX critical error — missing scrollbars — Fixed missing scrollbars causing a critical UX issue.
  • Wrong background color on the sidebar collapse button — Fixed the button's background color.
  • Line breaks on Enter key — Fixed text splitting behavior when pressing Enter.
  • Employees — Certificates subpanel modification — Fixed the Certificates subpanel behavior on Employee records.
  • Meeting duplication — field exceptions — Fixed field handling exceptions when duplicating a meeting.
  • Bug fixes found in Greens testing — Fixed several issues found during Greens testing, including problems with relate fields.
  • MintMCP production bug fixes — Fixed several bugs reported from production use of MintMCP.
  • Sidebar menu displaying incorrectly at different resolutions — Fixed responsive layout issues in the sidebar menu.
  • MintMCP meeting date errors — Fixed incorrect date handling for MCP-created meetings.
  • Unclear message when adding another Terms of Employment condition — Improved the error/warning message shown to the user.
  • Candidate relation not auto-filling on Candidature created from Candidate — Fixed relation propagation when creating a Candidature from a Candidate record.

Technical / Internal Changes

  • Cleanup of unused fields across modules — Removed unused fields to reduce module clutter.
  • Removal of #[AllowDynamicProperties] from API classes — Removed the attribute across all API classes ahead of future PHP compatibility requirements.
  • ConstantsLoader bug fixes and directory rename — Fixed scandir() warnings and unclear merge logic in ConstantsLoader, and renamed api/app/Constansts/ to api/app/Constants/.
  • MCP domain unification — subpath support — Unified the MCP domain to be served as a subpath.
  • Masquerade — ported latest version to core — Brought the latest Masquerade implementation into core.
  • MintMCP server migration to the official PHP SDK — Migrated the MCP server implementation to the official PHP SDK.
  • Entities — change in generation mechanism — Updated the entity generation mechanism.
  • MCP introduction / Unit test coverage — Investigative spikes covering MCP introduction and expanding unit test coverage.
  • SuiteCRM 7.14.9 upstream patches — Ported applicable fixes from SuiteCRM 7.14.9.
  • Removal of the committed root assets/ folder and root index.html — The pre-built Vue bundle that used to be committed at the repository root (the assets/ directory and the root index.html) is no longer needed. The .htaccess change now serves the SPA and its assets directly from vue/dist/, so these root artifacts became stale duplicates (the root index.html still referenced now-deleted ./assets/* files). The assets/ directory was removed; the root index.html is obsolete and can be deleted.

Upgrade Instructions

Upgrade procedure for this release

Normally, upgrading MintHCM is a single automated command — ./MintCLI upgrade — which fetches
and checks out the target version, sets file permissions, rebuilds the instance, and runs
migrations for you.

However, the automated upgrade command itself was broken and had to be fixed as part of this
release. Because the fix ships in 4.3.2, the automated ./MintCLI upgrade path cannot be used
to reach 4.3.2 cleanly. Upgrade to 4.3.2 manually instead:

  1. Pull the code — check out / pull the 4.3.2 tag (or master at this release).
  2. Set permissions — restore file ownership and permissions for the web server user
    (e.g. chown -R www-data:www-data . and the usual writable-directory permissions).
  3. Rebuild via MintCLI — run ./MintCLI instance:rebuild to repair and rebuild the instance.
  4. Fix .htaccess — the frontend (Vue) assets are now served from a different source
    (the old copy_vue_dist step was removed from the upgrade flow): assets and the SPA entry
    now come directly from vue/dist/. The root .htaccess must be updated accordingly — see
    the exact rules below.

From 4.3.2 onward the fixed ./MintCLI upgrade command can be used again for subsequent upgrades.

.htaccess changes

The authoritative template is legacy/MintCLI/src/Assets/.htaccess. Regenerate the instance root
.htaccess from it, keeping your instance's own RewriteBase (do not overwrite RewriteBase
with __BASE_PATH__ — replace that placeholder with your instance base path, e.g. / or /mint/).
./MintCLI instance:rebuild and the shipped upgrade scripts do this automatically; the manual
equivalent is below.

Old root artifacts are now obsolete. Before this release the built Vue bundle was committed at
the repository root as an assets/ folder plus a root index.html. With the frontend now served
straight from vue/dist/, both are redundant: the assets/ folder has been removed from the
repository, and the root index.html is stale (it still points at the deleted ./assets/* files)
and can be safely deleted. Do not re-add them — the DirectoryIndex/rewrite rules below take
care of serving the SPA.

a) Frontend now served from vue/dist/ (new — this is the "different source"):

DirectoryIndex vue/dist/index.html

# inside <IfModule mod_rewrite.c>
RewriteRule ^assets/(.*?)$ vue/dist/assets/$1 [L]
RewriteRule ^bg.jpg$ vue/dist/bg.jpg [L]
RewriteRule ^favicon.ico$ vue/dist/favicon.ico [L]

# SPA fallback — everything that is not a real file (and not the MCP path)
# is routed to the Vue entry point
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_URI} !/mcp/
RewriteRule ^ vue/dist/index.html [L]

b) No-cache headers on the SPA entry (so users get the new build after upgrade):

<IfModule mod_headers.c>
    <Files "index.html">
        Header set Cache-Control "no-store, no-cache, must-revalidate, max-age=0"
        Header set Pragma "no-cache"
        Header set Expires "Thu, 01 Jan 1970 00:00:00 GMT"
    </Files>
</IfModule>

c) MCP + OAuth well-known rules (subpath support, #187665) — insert right after the
RewriteRule ^api/(.*?)$ api/index.php [L] line:

RewriteRule ^mcp/?$ mcp/index.php [L,QSA]
RewriteRule ^\.well-known/oauth-protected-resource/mcp/?$ mcp/oauth.php [L,QSA,E=OAUTH_ENDPOINT:discovery]
RewriteRule ^\.well-known/oauth-authorization-server/mcp/?$ mcp/oauth.php [L,QSA,E=OAUTH_ENDPOINT:authorization]
RewriteRule ^\.well-known/openid-configuration/mcp/?$ mcp/oauth.php [L,QSA,E=OAUTH_ENDPOINT:authorization]
RewriteRule ^\.well-known/ - [R=404,L]

d) Hardening carried in the same template: deny direct access to .md files and block the
.claude / .ai directories:

<FilesMatch "(?i:\.md)$">
    Require all denied
</FilesMatch>

# inside <IfModule mod_rewrite.c>
RewriteRule ^(\.claude|\.ai)(/.*)?$ - [F,L]

The upgrade scripts back up the existing root .htaccess to .htaccess.bak.4.3.2 before rewriting
it, and are idempotent (they detect the vue/dist/index.html marker and skip if already applied).

Additional notes

  • Composer dependencies: run composer install in both api/ and legacy/ after checkout — api/composer.json and legacy/composer.json changed (including security-related package updates for jQuery, YUI, FullCalendar, jsTree).
  • Frontend assets: run npm install and rebuild in vue/ (npm run build:repo) — vue/package.json changed.
  • New modules: AIPromptTemplates, MCPDocCategories, and MCPDocumentation were added. Run Quick Repair and Rebuild from Admin after upgrade so the new modules, their vardefs, and relationships are registered.
  • API namespace rename: api/app/Constansts/ was renamed to api/app/Constants/. If any local customizations in api/custom/ reference the old Constansts namespace or path, update those references before deploying.
  • ESList removal: the legacy ESList module directory was removed. If any custom code or configuration references ESList views directly, migrate to the Vue list views before upgrading.
  • Authentication: OIDC and SAML support were added/extended, and SSO login now also accepts classic login/password. If SSO was previously the only login method enforced via custom configuration, review that configuration after upgrade.
  • PHP attribute cleanup: #[AllowDynamicProperties] was removed from API classes — custom code extending these classes that relied on dynamic properties should declare them explicitly.

Breaking Changes

  • Removed the legacy ESList module, which contained security issues and is now superseded by the Vue frontend.

Security Fixes

  • Content-Security-Policy header introduced.
  • Bundled third‑party JS libraries (jQuery, YUI, FullCalendar, jsTree) updated to patch known vulnerabilities.
  • Sensitive fields hidden in legacy API V8 endpoint.
  • Public access restricted for markdown documentation files.
  • Fixed self‑XSS via improper handling of `login_language` parameter.
  • Added missing parent‑record ACL check on subpanel endpoint (IDOR fix).
  • Sanitized `description` field to prevent stored XSS in Comments module.
  • Fixed authenticated SQL injection in legacy API V8 filter handling (`in`/`not_in`).
  • Restricted access to publicly accessible directories and files.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track minthcm

Get notified when new releases ship.

Sign up free

About minthcm

First AI‑enabled open-source Human Capital Management system that you can start using today.

All releases →

Related context

Related CVEs

Beta — feedback welcome: [email protected]