Skip to content

Tymeslot

v1.0.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

appointment appointment-booking appointment-scheduling appointments calendar calendars
+6 more
calendly-alternative docker elixir phoenix-liveview postgresql scheduling

Summary

AI summary

Prevent email header injection in subject lines, fixing a critical security vulnerability.

Full changelog

[1.0.3] — 2026-05-22

Bug Fixes

  • core: Allow moving events between calendar integrations
  • core: Prevent email header injection in subject lines
  • core: Use a neutral greeting in transactional emails when no name is set
  • core: Route demo meeting-type slug lookup through Demo facade
  • core: Respect calendar selection in meeting picker and grid
  • core: Show placeholder hints in form inputs
  • core: Prevent CalDAV event delete and update from failing through circuit breaker
  • core: Prevent Docker container from failing to restart with an existing volume

Features

  • core: Preserve special characters in meeting titles and labels

Security Fixes

  • Prevent email header injection in subject lines — mitigates RCE/SSRF risks (no CVE ID provided)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Tymeslot

Get notified when new releases ship.

Sign up free

About Tymeslot

Privacy-first scheduling platform

All releases →

Related context

Beta — feedback welcome: [email protected]