This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 1mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
docker
documentation
free
note-taking
notes
self-hosted
+4 more
tasks
todolist
web
wiki
Affected surfaces
auth
rce_ssrf
Summary
AI summaryFixed two security vulnerabilities: unsafe attachment imports and stored XSS in publicly shared notes.
Full changelog
Poznote 6.21.1
- Hardened file import and upload handling to address a vulnerability related to unsafe attachment imports.
- Fixed a stored XSS vulnerability in publicly shared notes by improving public note sanitization, tightening the Content Security Policy (CSP), and adding XSS regression test coverage.
- Fixed Excalidraw diagram alignment issues in public sharing.
Security Fixes
- Hardened file import and upload handling to address a vulnerability related to unsafe attachment imports.
- Fixed stored XSS vulnerability in publicly shared notes by improving sanitization, tightening CSP, and adding regression tests.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]