This release includes 1 security fix for security teams reviewing exposed deployments.
Published 8mo
File Storage & Sync
✓ No known CVEs patched
This release patches 1 known CVE
Topics
alist
aliyunpan
baidupan
openlist
Affected surfaces
rce_ssrf
Summary
AI summaryFixes Zip slip security vulnerability.
Full changelog
🚀 Features
- 189PC,189TV:
- Add refreshToken and qrcode login - by @foxxorcat in https://github.com/OpenListTeam/OpenList/issues/1205 (c15ae)
- alias:
- Support pass through provider - by @KirCute in https://github.com/OpenListTeam/OpenList/issues/1269 (bbb7c)
- drivers:
- local:
- Auto create recycle dir if not exists - by @tursom in https://github.com/OpenListTeam/OpenList/issues/1244 (1fe26)
- style:
- Add driver icons and disk usage - by @KirCute in https://github.com/OpenListTeam/OpenList/issues/1274 (cc16c)
🐞 Bug Fixes
- 123: Add get and list hash info - by @KirCute in https://github.com/OpenListTeam/OpenList/issues/1278 (61a8e)
- ci: Add tag_name to upload assets step - by @Suyunmeng in https://github.com/OpenListTeam/OpenList/issues/1234 (433dc)
- local: Cannot mkdir on specific platforms - by @KirCute in https://github.com/OpenListTeam/OpenList/issues/1304 (68433)
- security: Zip slip - by @hshpy in https://github.com/OpenListTeam/OpenList/issues/1228 (c1d03)
- stream: Http chucked upload issue - by @TwoOnefour in https://github.com/OpenListTeam/OpenList/issues/1152 (cbbb5)
View changes on GitHub
Security Fixes
- Zip slip vulnerability fixed — prevents path traversal during ZIP extraction.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]