This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+5 more
Affected surfaces
Summary
AI summaryStrengthened security for attachment uploads, OAuth scopes, and XSS sanitization while fixing critical crashes.
Full changelog
-
Added billing funnel analytics for paywall views, plan selections, checkout starts, and expired checkout sessions, enabling clearer visibility from pricing exposure to payment outcome.
-
Improved deployment and worker reliability by ensuring billing analytics dependencies are available in slim worker contexts, preventing startup crashes during space-data migration jobs.
-
Improved the admin “Configure data database” dialog so the core binding status, including host, database, and state, is shown quickly instead of waiting for cross-space relationship checks to finish.
-
Cross-space related information now loads progressively in the background, reducing the perceived loading time for BYODB space configuration.
-
Optimized the underlying related-space scan to improve performance and reduce delay in production admin workflows.
-
Added billing funnel analytics to make the path from paywall exposure to subscription outcome visible, covering paywall views, plan selections, checkout starts, and checkout abandonment.
-
Improved internal visibility into where users drop off during the purchase process, helping product and customer-facing teams identify friction between pricing pages, upgrade prompts, and Stripe checkout.
-
This is an instrumentation-only update with no intended changes to billing behavior, checkout flow, or user-facing purchase logic.
-
Improved V2 performance for large rollup duplication, inline table creation, and bulk delete workflows, reducing overhead in high-volume operations.
-
Optimized rollup backfills and bulk mutation handling while preserving existing behavior for realtime updates, audit logs, automation, trash, and undo/redo.
-
Validated the changes through paired V1/V2 performance lab runs and tracing to ensure regressions were addressed without changing user-facing contracts.
-
Fixed a crash that could occur when deleting a field with existing references, including the “Publish Public Release” field in the Launches table.
-
The delete confirmation dialog now opens reliably, and both confirm and cancel actions remain stable during field deletion.
-
Fixed first-time OAuth sign-in failures in generated apps using domain or open login, so new users can be created successfully instead of seeing “Failed to create user record.”
-
Improved reliability of app login user creation by ensuring the required audit context is available during public authentication callbacks.
-
Fixed an issue where hidden fields could appear as empty in the expanded record view even though the user was allowed to see their values.
-
Hidden field values are now loaded only when the “show hidden fields” option is enabled, avoiding unnecessary requests while keeping the expanded record view accurate.
-
Existing user preferences for showing hidden fields are preserved after the update, including preferences saved by older versions.
-
In shared views, hidden field loading now respects the share’s table scope to avoid failed requests when expanding linked records from other tables.
-
Fixed an issue where newly created bases were not always recorded as visited, helping subsequent workflows correctly recognize the base and continue as expected.
-
Improved performance of computed field propagation in BYODB environments, especially for large dependency graphs that previously caused repeated long-running update passes.
-
Reduced unnecessary reprocessing of already-handled dirty records, making multi-hop computed updates more efficient and stable at production scale.
-
Added regression coverage for multi-hop propagation to help prevent similar performance issues from returning.
-
Improved the embed configuration experience by adding bottom spacing so content no longer sits too close to the page edge.
-
Kept the embed popover visible and interactive during configuration, reducing interruptions when adjusting share/embed settings.
-
Strengthened security for attachment uploads by ensuring file storage paths are fully controlled by the server, preventing path traversal risks while preserving normal upload behavior.
-
Improved notification safety by sanitizing displayed user-generated content to block stored XSS attacks without breaking supported links, including relative preview/download URLs.
-
Corrected OAuth authorization behavior so tokens only receive scopes the user explicitly approved, preventing unintended permission escalation.
-
Added targeted coverage and related hardening around these security fixes to reduce regression risk.
-
Fixed an issue where BYODB workspaces using a non-public PostgreSQL schema could fail to process computed updates, causing formula, lookup, or rollup values to remain stale.
-
Improved computed update claiming so Teable consistently respects the configured data schema when processing background calculation tasks.
-
Improved the performance and reliability of v2 integrity checks for large workspaces by avoiding repeated full scans of active link field metadata.
-
Reduced database load during full-check and repair sessions by reusing link storage references within each session and querying only the fields required for validation.
-
Added a targeted database index to speed up active link field lookups used by orphaned link storage checks.
Security Fixes
- Attachment upload paths fully controlled by server to prevent path traversal
- OAuth authorization now limits tokens to explicitly approved scopes preventing permission escalation
- User-generated content sanitized in notifications to block stored XSS attacks while preserving links
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]