This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryUpdates Other, https://github.com/nextcloud/richdocuments/pull/5855, and https://github.com/nextcloud/richdocuments/pull/5846 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Dependency updates. Dependency updates. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Verify initiator token type. Verify initiator token type. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Ensure initiator server is trusted. Ensure initiator server is trusted. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Properly read from lazy cache. Properly read from lazy cache. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Allow multiple save as operations to work. Allow multiple save as operations to work. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Guard share attribute parse. Guard share attribute parse. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Remove redundant stream cleanup in convertFileTo(). Remove redundant stream cleanup in convertFileTo(). Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Add index for wopi expiry column. Add index for wopi expiry column. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Fixed
- Verify initiator token type by @elzody in #5855
- Ensure initiator server is trusted by @elzody in #5846
- Properly read from lazy cache by @elzody in #5836
- Allow multiple save as operations to work by @emberfiend in #5814
- Guard share attribute parse by @rikled in #5811
- Remove redundant stream cleanup in convertFileTo() by @nicfab in #5781
- Add index for wopi expiry column by @elzody in #5749
Other
- Dependency updates
Security Fixes
- Verify initiator token type (PR #5855)
- Ensure initiator server is trusted (PR #5846)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]