This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+5 more
ReleasePort's take
Moderate signalThis release fixes broken PDF subtype handling and image‑to‑PDF conversion while adding Azerbaijani and Turkish translations.
Why it matters: The critical security fact adds impact statements for CVE-2026-7010 (severity 90) and CVE-2026-8829, requiring immediate attention from security teams.
Summary
AI summaryUpdates deps, Version Information, and feat across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Adds impact statements for CVE-2026-7010 and CVE-2026-8829. Adds impact statements for CVE-2026-7010 and CVE-2026-8829. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Feature | Low |
Adds Azerbaijani translations for the application. Adds Azerbaijani translations for the application. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Feature | Low |
Adds Turkish translations for the application. Adds Turkish translations for the application. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Feature | Low |
Adds subpath routing support via BASE_URL for reverse proxies. Adds subpath routing support via BASE_URL for reverse proxies. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Dependency | Low |
Updates lxml to version 6.1.1. Updates lxml to version 6.1.1. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Dependency | Low |
Updates Pandoc to version 3.10. Updates Pandoc to version 3.10. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Dependency | Low |
Updates PyJWT, fastapi, and uvicorn in requirements.txt. Updates PyJWT, fastapi, and uvicorn in requirements.txt. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Dependency | Low |
Bumps react-router, react-router-dom, and brace-expansion. Bumps react-router, react-router-dom, and brace-expansion. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Bugfix | Medium |
Fixes broken PDF subtype handling and image-to-PDF conversion. Fixes broken PDF subtype handling and image-to-PDF conversion. Source: llm_adapter@2026-06-12 Confidence: high |
— |
Full changelog
Fixes a bug with PDF type detection / conversions.
Adds Azerbaijani and Turkish translations (thanks @Elvin0802).
Adds subpath routing support for reverse proxies (thanks @SimonLou-Dev).
Changes
- feat: add BASE_URL for subpath rooting (#176) (c256906)
- feat: Add Turkish translations for the application. (#178) (58a920f)
- feat: Add Azerbaijani translations for the application. (#177) (45d2662)
- fix: broken subtype PDF handling and image-to-PDF conversion support … (#180) (ff4aaaa)
- fix: Just small things (#172) (82d245f)
- chore(vex): add CVE-2026-7010 and CVE-2026-8829 impact statements (9e93a8d)
- chore(deps): update lxml version to 6.1.1 (d7ce08c)
- chore(deps): update Pandoc version to 3.10 (fixes #173) (8d3a77f)
- chore(deps): update PyJWT, fastapi, and uvicorn versions in requirements.txt (cb28642)
- chore(deps): bump react-router, react-router-dom, and brace-expansion (#171) (1a0dfb7)
Version Information
- Full version:
v1.3.1 - Minor version tag:
v1.3 - Major version tag:
v1
Updated Tags
v1.3→v1.3.1(updated)v1→v1.3.1(updated)
Security Fixes
- CVE-2026-7010 — impact statement added for Vex dependency
- CVE-2026-8829 — impact statement added for Vex dependency
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]