This release patches 2 CVEs for security teams tracking exposure across their dependency inventory.
Published 26d
Productivity & Wikis
2 patched CVEs
This release patches 2 known CVEs
CVE-2026-42208
EPSS 87%
CVE-2026-42271
EPSS 80%
2
CVEs patched
Topics
cookbook
cooking
django
docker
food
markdown
+5 more
meal-planner
recipe
recipes
self-hosted
shopping
Affected surfaces
auth
breaking_upgrade
Summary
AI summaryFixed manipulation of private recipes via the steps API.
Full changelog
- fixed private recipes could be manipulated by space users trough steps API https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-wjf3-fq5w-7j7w
- updated translations
Security Fixes
- GHSA-wjf3-fq5w-7j7w — prevented space users from manipulating private recipes through the steps API
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About recipes
Application for managing recipes, planning meals, building shopping lists and much much more!
Beta — feedback welcome: [email protected]