Skip to content

spupuz/VibeNVR

v1.30.5 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Media Servers
โœ“ No known CVEs patched
Read the diff โ†’ Tool health โ†’ What is this tool? โ†’
This release patches 2 known CVEs

Topics

ffmpeg lightweight local-storage nvr opensource privacy
+1 more
video-surveillance

Affected surfaces

rce_ssrf breaking_upgrade

Summary

AI summary

Updates ๐Ÿ› ๏ธ Key Improvements, ๐Ÿ™Œ Contributors, and ๐Ÿš€ Release v1.30.5 across a mixed release.

Full changelog

๐Ÿš€ Release v1.30.5

๐Ÿ“ Summary

VibeNVR v1.30.5 is a significant maintenance and code-health update that integrates dozens of critical security patches, architectural refinements, and UI accessibility improvements. We have fully stabilized the engine, mitigated critical path traversal and SQL injection vulnerabilities, and seamlessly integrated go2rtc routing capabilities.

๐Ÿ› ๏ธ Key Improvements

  • ๐Ÿ›ก๏ธ Security: Mitigated severe SQL Injection vectors in database migration scripts and neutralized Path Traversal vulnerabilities in avatar upload/deletion pipelines.
  • ๐Ÿš€ Engine & Core: Resolved a global AI detection deadlock by implementing a robust passive watchdog in AIDetector. Integrated go2rtc proxy lifecycle management.
  • ๐ŸŽจ Aesthetics & UI: Significantly enhanced accessibility (A11y) across the application with proper ARIA labels. Added an auto-fill "Use these streams" button for ONVIF profiles to improve the camera setup experience.
  • โšก Performance: Optimized React Timeline components and Camera Cards with memoization (React.memo) to eliminate unnecessary re-renders. Cleaned up multiple legacy dependencies and unused imports (tarfile, sys).

๐Ÿ™Œ Contributors

  • @spupuz: Core architectural refactoring, RBAC enhancements, and AI watchdog implementation.
  • @yura.bilous (ะฎั€ั–ะน ะ‘ั–ะปะพัƒั): ONVIF stream auto-fill implementation and Timeline React state fixes.
  • @google-labs-jules: Automated code health, SAST security audits, and ARIA label accessibility updates.

Security Fixes

  • Mitigated severe SQL Injection vulnerabilities in database migration scripts
  • Neutralized Path Traversal vulnerabilities in avatar upload/deletion pipelines

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track spupuz/VibeNVR

Get notified when new releases ship.

Sign up free

About spupuz/VibeNVR

All releases โ†’

Related context

Earlier breaking changes

  • v1.29.7 Removed the legacy `stream_url` schema from stream routing.
  • v1.28.3 Must update docker-compose.yml with TZ variable for all services

Beta — feedback welcome: [email protected]