Skip to content

poznote

v6.21.1 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

docker documentation free note-taking notes self-hosted
+4 more
tasks todolist web wiki

Affected surfaces

auth rce_ssrf

Summary

AI summary

Fixed two security vulnerabilities: unsafe attachment imports and stored XSS in publicly shared notes.

Full changelog

Poznote 6.21.1

  • Hardened file import and upload handling to address a vulnerability related to unsafe attachment imports.
  • Fixed a stored XSS vulnerability in publicly shared notes by improving public note sanitization, tightening the Content Security Policy (CSP), and adding XSS regression test coverage.
  • Fixed Excalidraw diagram alignment issues in public sharing.

Security Fixes

  • Hardened file import and upload handling to address a vulnerability related to unsafe attachment imports.
  • Fixed stored XSS vulnerability in publicly shared notes by improving sanitization, tightening CSP, and adding regression tests.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track poznote

Get notified when new releases ship.

Sign up free

About poznote

Poznote is a personal note-taking and documentation platform.

All releases →

Related context

Beta — feedback welcome: [email protected]