Skip to content

spupuz/VibeNVR

v1.30.12 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 26d Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ffmpeg lightweight local-storage nvr opensource privacy
+1 more
video-surveillance

Affected surfaces

deps

Summary

AI summary

Updates 🛠️ Key Improvements, 🙌 Contributors, and 🚀 Release v1.30.12 across a mixed release.

Full changelog

🚀 Release v1.30.12

📝 Summary

This release focuses on optimizing backend performance, improving frontend accessibility, and bolstering system security. We've resolved critical N+1 query bottlenecks during data serialization, ensuring smooth scaling. On the UI side, we've enriched interactive components with ARIA labels to ensure compliance and better usability. Finally, we applied crucial patches to both our AI detection engine and upstream dependencies.

🛠️ Key Improvements

  • 🚀 Performance: Resolved severe N+1 database query issues in bulk deletion APIs and backup data generation, optimizing serialization operations for large instances.
  • 🛡️ Security: Patched a High severity vulnerability in the Vite development dependency (CVE-2026-53571) preventing alternate path traversal bypasses.
  • 🧠 AI Engine: Addressed a critical bug that caused AI detection threads to silently drop and deactivate when the manager's global configuration desynchronized.
  • 🎨 Aesthetics & Accessibility: Upgraded the frontend Palette design system, introducing semantic ARIA attributes and localized texts across live view interfaces, PTZ controls, and User Management action buttons.

🙌 Contributors

  • @Lion-killer: Fixed critical AI detection desync bug in engine (#153)
  • @spupuz: N+1 performance optimizations, ARIA accessibility improvements, and localization enhancements (#145, #147, #148, #149, #151, #152)

Security Fixes

  • CVE-2026-53571 — High severity path traversal bypass vulnerability patched in Vite development dependency

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track spupuz/VibeNVR

Get notified when new releases ship.

Sign up free

About spupuz/VibeNVR

All releases →

Related context

Earlier breaking changes

  • v1.29.7 Removed the legacy `stream_url` schema from stream routing.
  • v1.28.3 Must update docker-compose.yml with TZ variable for all services

Beta — feedback welcome: [email protected]