This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Media Servers
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ffmpeg
lightweight
local-storage
nvr
opensource
privacy
+1 more
video-surveillance
Affected surfaces
rce_ssrf
Summary
AI summary[CRITICAL] Prevent argument injection in ffprobe subprocess calls
Full changelog
What's Changed
- 🎨 Palette: Enhance Accessibility with ARIA Labels and States by @spupuz in https://github.com/spupuz/VibeNVR/pull/138
- 🎨 Palette: Add aria-labels to icon-only buttons in GroupsManager by @spupuz in https://github.com/spupuz/VibeNVR/pull/139
- ⚡ Bolt: Optimize _get_detailed_storage_stats by @spupuz in https://github.com/spupuz/VibeNVR/pull/140
- 🎨 Palette: Add semantic ARIA attributes to custom toggle switches by @spupuz in https://github.com/spupuz/VibeNVR/pull/142
- 🛡️ Sentinel: [CRITICAL] Prevent argument injection in ffprobe subprocess calls by @spupuz in https://github.com/spupuz/VibeNVR/pull/143
Full Changelog: https://github.com/spupuz/VibeNVR/compare/v1.30.9...v1.30.10
Security Fixes
- [CRITICAL] Prevent argument injection in ffprobe subprocess calls
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About spupuz/VibeNVR
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]