This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalVersion 1.3.5 fixes a critical authentication forgery vulnerability and prevents sensitive data from being sent to browsers.
Why it matters: The release patches a forged‑authentication flaw (severity 95) and stops PINs/secrets from leaking to the browser, directly reducing credential theft risk.
Summary
AI summaryFixed authentication forgery vulnerability and hid sensitive fields in UI.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixed vulnerability allowing forged authentication Fixed vulnerability allowing forged authentication Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Security | High |
Strengthened authentication and session security across the app Strengthened authentication and session security across the app Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Security | High |
Sensitive information (PINs, secrets) no longer sent to browser Sensitive information (PINs, secrets) no longer sent to browser Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Security | High |
Sensitive fields hidden when editing; leave blank to retain current value Sensitive fields hidden when editing; leave blank to retain current value Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Security | High |
Tightened access controls on administrative and family‑management features Tightened access controls on administrative and family‑management features Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Security | Medium |
Added extra logging for administrative actions Added extra logging for administrative actions Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Self‑hosted deployments now auto‑generate unique JWT security key during setup and upgrades Self‑hosted deployments now auto‑generate unique JWT security key during setup and upgrades Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Fixed issue preventing family System PIN change when individual caretakers are configured Fixed issue preventing family System PIN change when individual caretakers are configured Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
v1.3.5 - Security and Privacy Patch
Changes
Security & Privacy
- Fixed security vulnerability that allowed users to forge authentication - Thank you myoann!
- Strengthened authentication and session security across the app
- Improved protection of sensitive information in system pages - PINs, and configuration secrets are no longer sent to the browser
- Sensitive fields (PINs, passwords, API keys) are now hidden when editing; leave them blank to keep the current value, or enter a new value to change it
- Tightened access controls on administrative and family-management features
- Added extra logging for administrative actions
- Self-hosted deployments now automatically generate a unique JWT security key during setup and upgrades
Bugfixes
- Fixed an issue that prevented the family System PIN from being changed while individual caretakers were configured
Security Fixes
- Fixed authentication forgery vulnerability that allowed users to forge authentication (reported by myoann)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sprout-track
A tracker to track baby diapers, feedings, naps, pumping, and other activities.
Related context
Related tools
Beta — feedback welcome: [email protected]