This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryUpdates Other, https://github.com/nextcloud/richdocuments/pull/5856, and https://github.com/nextcloud/richdocuments/pull/5847 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Verify initiator token type. Verify initiator token type. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Ensure initiator server is trusted. Ensure initiator server is trusted. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Correctly load via direct editing. Correctly load via direct editing. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Properly read from lazy cache. Properly read from lazy cache. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Allow multiple save‑as operations to work. Allow multiple save‑as operations to work. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Guard share attribute parse. Guard share attribute parse. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Remove redundant stream cleanup in convertFileTo(). Remove redundant stream cleanup in convertFileTo(). Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Add index for wopi expiry column. Add index for wopi expiry column. Source: llm_adapter@2026-07-15 Confidence: low |
— |
Full changelog
Fixed
- Verify initiator token type by @elzody in #5856
- Ensure initiator server is trusted by @elzody in #5847
- Correctly load via direct editing by @elzody in #5838
- Properly read from lazy cache by @elzody in #5837
- Allow multiple save as operations to work by @emberfiend in #5815
- Guard share attribute parse by @rikled in #5812
- Remove redundant stream cleanup in convertFileTo() by @nicfab in #5780
- Add index for wopi expiry column by @elzody in #5750
Other
- Dependency updates
- More tests
Security Fixes
- Verify initiator token type and ensure initiator server is trusted, closing related validation vulnerabilities
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]