This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryDisable forgot‑password via email if ALLOWED_HOSTS is unset, fixing a high‑severity vulnerability (GHSA-9x2r-5pff-8w6c).
Full changelog
- This is a security release: fix 2 high vulnerabilities
- Disable forgot password functionality via email if ALLOWED_HOSTS is unset (https://github.com/Syslifters/sysreptor/security/advisories/GHSA-9x2r-5pff-8w6c)
- Details for a second vulnerability have been temporarily withheld and will be disclosed at a later date
- Enable/disable plugins in settings web UI
- Enable some plugins by default
- Allow SSO identity API for API token auth
- Restore archive: different message filename per key
- AI agent: Confirm delete when reverting changes
Click here to go to the update instructions: https://docs.sysreptor.com/setup/updates/
Security Fixes
- GHSA-9x2r-5pff-8w6c — Disable forgot‑password via email if ALLOWED_HOSTS is unset (high severity)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sysreptor
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
Related context
Related tools
Beta — feedback welcome: [email protected]