Skip to content

sprout-track

v1.3.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

activity baby tracker tracking

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 10d

Version 1.3.5 fixes a critical authentication forgery vulnerability and prevents sensitive data from being sent to browsers.

Why it matters: The release patches a forged‑authentication flaw (severity 95) and stops PINs/secrets from leaking to the browser, directly reducing credential theft risk.

Summary

AI summary

Fixed authentication forgery vulnerability and hid sensitive fields in UI.

Changes in this release

Security Critical

Fixed vulnerability allowing forged authentication

Fixed vulnerability allowing forged authentication

Source: llm_adapter@2026-07-16

Confidence: high

Security High

Strengthened authentication and session security across the app

Strengthened authentication and session security across the app

Source: llm_adapter@2026-07-16

Confidence: high

Security High

Sensitive information (PINs, secrets) no longer sent to browser

Sensitive information (PINs, secrets) no longer sent to browser

Source: llm_adapter@2026-07-16

Confidence: high

Security High

Sensitive fields hidden when editing; leave blank to retain current value

Sensitive fields hidden when editing; leave blank to retain current value

Source: llm_adapter@2026-07-16

Confidence: high

Security High

Tightened access controls on administrative and family‑management features

Tightened access controls on administrative and family‑management features

Source: llm_adapter@2026-07-16

Confidence: high

Security Medium

Added extra logging for administrative actions

Added extra logging for administrative actions

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Self‑hosted deployments now auto‑generate unique JWT security key during setup and upgrades

Self‑hosted deployments now auto‑generate unique JWT security key during setup and upgrades

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Fixed issue preventing family System PIN change when individual caretakers are configured

Fixed issue preventing family System PIN change when individual caretakers are configured

Source: llm_adapter@2026-07-16

Confidence: high

Full changelog

v1.3.5 - Security and Privacy Patch

Changes

Security & Privacy

  • Fixed security vulnerability that allowed users to forge authentication - Thank you myoann!
  • Strengthened authentication and session security across the app
  • Improved protection of sensitive information in system pages - PINs, and configuration secrets are no longer sent to the browser
  • Sensitive fields (PINs, passwords, API keys) are now hidden when editing; leave them blank to keep the current value, or enter a new value to change it
  • Tightened access controls on administrative and family-management features
  • Added extra logging for administrative actions
  • Self-hosted deployments now automatically generate a unique JWT security key during setup and upgrades

Bugfixes

  • Fixed an issue that prevented the family System PIN from being changed while individual caretakers were configured

Security Fixes

  • Fixed authentication forgery vulnerability that allowed users to forge authentication (reported by myoann)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track sprout-track

Get notified when new releases ship.

Sign up free

About sprout-track

A tracker to track baby diapers, feedings, naps, pumping, and other activities.

All releases →

Related context

Beta — feedback welcome: [email protected]