Skip to content

outline

v1.8.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

docker javascript mobx nodejs react slack
+1 more
wiki

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

The release adds protection against timing attacks on the notification unsubscribe endpoint.

Why it matters: Mitigates a critical security risk (severity 80) for the notification unsubscribe surface; operators should apply the update immediately.

Summary

AI summary

Added protection against timing attacks on notification unsubscribe endpoints.

Changes in this release

Security High

Adds protection against timing attacks on notification unsubscribe endpoints.

Adds protection against timing attacks on notification unsubscribe endpoints.

Source: llm_adapter@2026-06-06

Confidence: high

Feature Medium

Adds admin interface to change user avatars.

Adds admin interface to change user avatars.

Source: llm_adapter@2026-06-06

Confidence: high

Feature Medium

Adds automatic metrics tagging of outgoing emails.

Adds automatic metrics tagging of outgoing emails.

Source: llm_adapter@2026-06-06

Confidence: high

Feature Medium

Increases valid user‑supplied URL length to 1024 characters.

Increases valid user‑supplied URL length to 1024 characters.

Source: llm_adapter@2026-06-06

Confidence: high

Feature Medium

Adds email verification check during sign‑in flow.

Adds email verification check during sign‑in flow.

Source: llm_adapter@2026-06-06

Confidence: high

Feature Low

Enables drag-and-drop from document lists.

Enables drag-and-drop from document lists.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Feature Low

Allows collection managers to approve access requests.

Allows collection managers to approve access requests.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Feature Low

Makes collection title and icon inline editable like documents.

Makes collection title and icon inline editable like documents.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Performance Medium

Improves worker performance through caching.

Improves worker performance through caching.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Fixes search term highlights missing on navigation from search.

Fixes search term highlights missing on navigation from search.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Fixes intermittent sidebar element not active on first load.

Fixes intermittent sidebar element not active on first load.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Prevents scrollbar from causing horizontal movement in comments sidebar.

Prevents scrollbar from causing horizontal movement in comments sidebar.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Adds handling of unhandled server error in MCP route.

Adds handling of unhandled server error in MCP route.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Low

Prevents icon picker from auto-closing on choice.

Prevents icon picker from auto-closing on choice.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Bugfix Low

Fixes sticky table header styling in Safari.

Fixes sticky table header styling in Safari.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Bugfix Low

Treats private IP lookup as invalid request instead of internal error.

Treats private IP lookup as invalid request instead of internal error.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Bugfix Low

Resolves iterable error for collaboratorIds with very old documents.

Resolves iterable error for collaboratorIds with very old documents.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Bugfix Low

Fixes correct support for hard break serialization in commonMark.

Fixes correct support for hard break serialization in commonMark.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Full changelog

What's Changed

Improvements

  • Drag-and-drop now supports dragging from document lists in https://github.com/outline/outline/pull/12587
  • Add admin interface to change user avatars in https://github.com/outline/outline/pull/12405
  • Add automatic metrics tagging of outgoing emails in https://github.com/outline/outline/pull/12570
  • Various improvements to mobile styling and layout in https://github.com/outline/outline/pull/12577, https://github.com/outline/outline/pull/12576

Fixes

  • Fixed search term highlights missing on navigation from search in https://github.com/outline/outline/pull/12598
  • Fixed an intermitent issue where sidebar element is not correctly active on first load in https://github.com/outline/outline/pull/12566
  • Scrollbar no longer causes horizontal movement in comments sidebar in https://github.com/outline/outline/pull/12565
  • Added protection against timing attacks on notification unsubscribe endpoints in https://github.com/outline/outline/pull/12551
  • Icon picker is no longer auto-closed on choice in https://github.com/outline/outline/pull/12573
  • Access requests can now be approved by collection managers in https://github.com/outline/outline/pull/12579
  • Collection title and icon inline are now editable like documents in https://github.com/outline/outline/pull/12574
  • Increased valid user-supplied URL length to 1024 in https://github.com/outline/outline/pull/12585
  • Added handling of unhandled server error in MCP route in https://github.com/outline/outline/pull/12586
  • Fixed sticky table header styling in Safari in https://github.com/outline/outline/pull/12590
  • Private IP lookup is now invalid request rather than internal error in https://github.com/outline/outline/pull/12592
  • Improved worker performance through caching in https://github.com/outline/outline/pull/12593
  • chore: Improve handling of "expected" network errors from webhooks in https://github.com/outline/outline/pull/12599
  • Mermaid is no longer persisted as last used coding language in https://github.com/outline/outline/pull/12601
  • Fixed collaboratorIds iterable error when handling very old documents in https://github.com/outline/outline/pull/12602
  • Fixed correct support for hard break serialization for commonMark in https://github.com/outline/outline/pull/12603
  • Added email verification check during sign-in flow in https://github.com/outline/outline/pull/12605

Full Changelog: https://github.com/outline/outline/compare/v1.8.0...v1.8.1

Security Fixes

  • Added protection against timing attacks on notification unsubscribe endpoints (GHSA‑f3c9‑4g2b‑6w7r)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track outline

Get notified when new releases ship.

Sign up free

About outline

The fastest knowledge base for growing teams. Beautiful, realtime collaborative, feature packed, and markdown compatible.

All releases →

Related context

Earlier breaking changes

  • v1.9.0 Reject `collections.update` requests containing both `description` and `data`.
  • v1.9.0 Newly created collections via MCP default to private visibility.
  • v1.9.0 `document_update` and `collection_update` tools now error when no changes occur.

Beta — feedback welcome: [email protected]