This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 22d
Secrets & Credentials
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
aes256
encryption
go
one-time-secret
Affected surfaces
auth
rce_ssrf
Summary
AI summaryUpdates sec, deps, and https://github.com/Luzifer/ots/security/advisories/GHSA-6ppq-9x26-5r92 across a mixed release.
Full changelog
- Bugfixes
- fix(sec): putting JSON into string make XSS possible
- fix(sec): zero expiry creates non-expiring storage entries (see GHSA-6ppq-9x26-5r92)
- fix(sec): race between read and delete when using redis/valkey (see GHSA-92r4-rpw3-7cwm)
- fix(deps): update dependency @fortawesome/fontawesome-free to v7.3.0 (#432)
- fix(deps): update dependency vue to v3.5.39 (#431)
Security Fixes
- GHSA-6ppq-9x26-5r92 — JSON injection leading to XSS when converting JSON to string
- GHSA-6ppq-9x26-5r92 — Zero expiry creates non‑expiring storage entries
- GHSA-92r4-rpw3-7cwm — Race condition between read and delete operations in Redis/Valkey
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About ots
One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser
Related context
Beta — feedback welcome: [email protected]