Skip to content

Part-DB

v2.12.2 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Relational Databases
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

database electronics inventory inventory-management inventory-management-system inventory-system
+6 more
mysql part-db php symfony symfony-application symfony5

Affected surfaces

auth

ReleasePort's take

Light signal
editorial:auto 1mo

This release patches two XSS vulnerabilities affecting the project BOM import UI and table UI.

Why it matters: XSS flaws (severity 60) in critical UI surfaces can compromise user data; upgrade to v2.12.2 immediately.

Summary

AI summary

Updates Bug fixes, Other changes, and Security fixes across a mixed release.

Changes in this release

Security Medium

Fixes XSS vulnerability in project BOM import.

Fixes XSS vulnerability in project BOM import.

Source: llm_adapter@2026-06-14

Confidence: high

Security Medium

Fixes XSS vulnerability in project BOM table.

Fixes XSS vulnerability in project BOM table.

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Fixes invalid reference in API documentation.

Fixes invalid reference in API documentation.

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Fixes sidebar hide state not persisting over page reloads.

Fixes sidebar hide state not persisting over page reloads.

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Low

Prevents logging of deprecations to avoid large log files; small performance boost.

Prevents logging of deprecations to avoid large log files; small performance boost.

Source: llm_adapter@2026-06-14

Confidence: low

Bugfix Low

Disables logging of deprecations by default to reduce log size; optional reenable via env setting provides minor performance improvement.

Disables logging of deprecations by default to reduce log size; optional reenable via env setting provides minor performance improvement.

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Full changelog

[!IMPORTANT]
This version contains security fixes, it is recommended to update to this version immediately.

[!IMPORTANT]
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8

Part-DB 2.12.2

Security fixes

  • MEDIUM: Fixed XSS vulnerability in project BOM import
  • MEDIUM: Fixed XSS vulnerability in project BOM table

Bug fixes

  • Fixed invalid reference in api docs (PR #1403, @d-buchmann)
  • Fixed problem that sidebar hide state was not persisted over page reloads (PR #1404, @d-buchmann)
  • Do not log deprecations as the files can quickly get very large, old behavior can be reenabled via env setting. This might also give a small performance boost (fixes #1405)

Other changes

  • Updated KiCad symbols
  • Updated dependencies
  • Fixed deprecations

Full Changelog: https://github.com/Part-DB/Part-DB-server/compare/v2.12.1...v2.12.2

Security Fixes

  • MEDIUM: Fixed XSS vulnerability in project BOM import
  • MEDIUM: Fixed XSS vulnerability in project BOM table

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Part-DB

Get notified when new releases ship.

Sign up free

About Part-DB

Inventory management system for your electronic components.

All releases →

Related context

Beta — feedback welcome: [email protected]