Skip to content

Part-DB

v2.12.3 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Relational Databases
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

database electronics inventory inventory-management inventory-management-system inventory-system
+6 more
mysql part-db php symfony symfony-application symfony5

Summary

AI summary

Updates Security fixes, Other changes, and Part-DB 2.12.3 across a mixed release.

Full changelog

[!IMPORTANT]
This version contains security fixes, it is recommended to update to this version immediately.

[!IMPORTANT]
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8

Part-DB 2.12.3

Security fixes

  • Fixed missing SVG sanitatization, when file was uploaded with non-svg extension
  • Added CSP headers to static files, to prevent script execution, should an vulnerable file be uploaded somehow

Other changes

  • Updated KiCad symbols
  • Updated dependencies

Full Changelog: https://github.com/Part-DB/Part-DB-server/compare/v2.12.2...v2.12.3

Security Fixes

  • Fixed missing SVG sanitatization for uploads with non‑SVG extensions
  • Added CSP headers to static files to prevent script execution from uploaded content

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Part-DB

Get notified when new releases ship.

Sign up free

About Part-DB

Inventory management system for your electronic components.

All releases →

Related context

Beta — feedback welcome: [email protected]