This release includes 1 security fix for security teams reviewing exposed deployments.
Published 3mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
appointment
appointment-booking
appointment-scheduling
appointments
calendar
calendars
+6 more
calendly-alternative
docker
elixir
phoenix-liveview
postgresql
scheduling
Affected surfaces
auth
rbac
Summary
AI summaryPrevent calendar grid crashes on invalid timezones and extend IDOR prevention to booking reschedule/cancel flows.
Full changelog
[0.100.7] — 2026-04-17
Bug Fixes
- core: Prevent calendar grid crash on invalid user timezone
- core: Extend IDOR prevention to booking-form reschedule paths
- core: Prevent IDOR on meeting cancel/reschedule
- core: Emit METHOD:PUBLISH cancellations and harden ICS parameters
- core: Allow Stripe billing and checkout hosts in CSP form-action
- core: Create default weekly schedule for OAuth users
Security Fixes
- Extend IDOR prevention to booking-form reschedule paths and meeting cancel/reschedule actions
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]