Skip to content

ots

v1.21.8 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 22d Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

aes256 encryption go one-time-secret

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates sec, deps, and https://github.com/Luzifer/ots/security/advisories/GHSA-6ppq-9x26-5r92 across a mixed release.

Full changelog
  • Bugfixes
    • fix(sec): putting JSON into string make XSS possible
    • fix(sec): zero expiry creates non-expiring storage entries (see GHSA-6ppq-9x26-5r92)
    • fix(sec): race between read and delete when using redis/valkey (see GHSA-92r4-rpw3-7cwm)
    • fix(deps): update dependency @fortawesome/fontawesome-free to v7.3.0 (#432)
    • fix(deps): update dependency vue to v3.5.39 (#431)

Security Fixes

  • GHSA-6ppq-9x26-5r92 — JSON injection leading to XSS when converting JSON to string
  • GHSA-6ppq-9x26-5r92 — Zero expiry creates non‑expiring storage entries
  • GHSA-92r4-rpw3-7cwm — Race condition between read and delete operations in Redis/Valkey

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track ots

Get notified when new releases ship.

Sign up free

About ots

One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser

All releases →

Beta — feedback welcome: [email protected]