This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
ReleasePort's take
Moderate signalUpgrade idna to version 3.15 or later to remediate CVE‑2026‑45409.
Why it matters: CVE‑2026‑45409 (CVSS 9.0) affects all deployments using idna <3.15; immediate patching prevents remote code execution.
Summary
AI summaryBackend now prevents access to unready files, agents fixed metadata‑collector bug and replaced deprecated room options API, and frontend updated JavaScript dependencies.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Upgrade idna to >=3.15 addressing CVE-2026-45409 Upgrade idna to >=3.15 addressing CVE-2026-45409 Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Add file‑specific admin capability in backend Add file‑specific admin capability in backend Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Dependency | Low |
Update Python dependencies in backend Update Python dependencies in backend Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Dependency | Low |
Update JavaScript dependencies in frontend Update JavaScript dependencies in frontend Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | Medium |
Fix bug when closing metadata-collector in agents Fix bug when closing metadata-collector in agents Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | Medium |
Prevent accessing files if they are not ready in backend Prevent accessing files if they are not ready in backend Source: llm_adapter@2026-06-04 Confidence: low |
— |
| Bugfix | Low |
Make ffmpeg quiet in summary processing Make ffmpeg quiet in summary processing Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Refactor | Low |
Replace deprecated room options API in agents Replace deprecated room options API in agents Source: llm_adapter@2026-06-04 Confidence: high |
— |
Full changelog
What's Changed
Added
- ✨(backend) add file specific admin #1387
Changed
- 🐛(agents) fix bug when closing metadata-collector
- ⬆️(dependencies) update python dependencies
- ⬆️(frontend) update js dependencies
- ♻️(agents) replace deprecated room options API
Fixed
- 🔇(summary) make ffmpeg quiet #1404
- 🔒️(backend) prevent accessing files if they are not ready #1395
- ⬆️(backend) upgrade idna to >=3.15 to address CVE-2026-45409
Full Changelog: https://github.com/suitenumerique/meet/compare/v1.18.0...v1.19.0
Security Fixes
- CVE-2026-45409 — upgraded idna to >=3.15 in backend
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]