This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
ReleasePort's take
Light signalThis release patches two XSS vulnerabilities affecting the project BOM import UI and table UI.
Why it matters: XSS flaws (severity 60) in critical UI surfaces can compromise user data; upgrade to v2.12.2 immediately.
Summary
AI summaryUpdates Bug fixes, Other changes, and Security fixes across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Fixes XSS vulnerability in project BOM import. Fixes XSS vulnerability in project BOM import. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Security | Medium |
Fixes XSS vulnerability in project BOM table. Fixes XSS vulnerability in project BOM table. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Bugfix | Medium |
Fixes invalid reference in API documentation. Fixes invalid reference in API documentation. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Bugfix | Medium |
Fixes sidebar hide state not persisting over page reloads. Fixes sidebar hide state not persisting over page reloads. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Bugfix | Low |
Prevents logging of deprecations to avoid large log files; small performance boost. Prevents logging of deprecations to avoid large log files; small performance boost. Source: llm_adapter@2026-06-14 Confidence: low |
— |
| Bugfix | Low |
Disables logging of deprecations by default to reduce log size; optional reenable via env setting provides minor performance improvement. Disables logging of deprecations by default to reduce log size; optional reenable via env setting provides minor performance improvement. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
Full changelog
[!IMPORTANT]
This version contains security fixes, it is recommended to update to this version immediately.
[!IMPORTANT]
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Part-DB 2.12.2
Security fixes
- MEDIUM: Fixed XSS vulnerability in project BOM import
- MEDIUM: Fixed XSS vulnerability in project BOM table
Bug fixes
- Fixed invalid reference in api docs (PR #1403, @d-buchmann)
- Fixed problem that sidebar hide state was not persisted over page reloads (PR #1404, @d-buchmann)
- Do not log deprecations as the files can quickly get very large, old behavior can be reenabled via env setting. This might also give a small performance boost (fixes #1405)
Other changes
- Updated KiCad symbols
- Updated dependencies
- Fixed deprecations
Full Changelog: https://github.com/Part-DB/Part-DB-server/compare/v2.12.1...v2.12.2
Security Fixes
- MEDIUM: Fixed XSS vulnerability in project BOM import
- MEDIUM: Fixed XSS vulnerability in project BOM table
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]