This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
appointment
appointment-booking
appointment-scheduling
appointments
calendar
calendars
+6 more
calendly-alternative
docker
elixir
phoenix-liveview
postgresql
scheduling
Summary
AI summaryPrevent email header injection in subject lines, fixing a critical security vulnerability.
Full changelog
[1.0.3] — 2026-05-22
Bug Fixes
- core: Allow moving events between calendar integrations
- core: Prevent email header injection in subject lines
- core: Use a neutral greeting in transactional emails when no name is set
- core: Route demo meeting-type slug lookup through Demo facade
- core: Respect calendar selection in meeting picker and grid
- core: Show placeholder hints in form inputs
- core: Prevent CalDAV event delete and update from failing through circuit breaker
- core: Prevent Docker container from failing to restart with an existing volume
Features
- core: Preserve special characters in meeting titles and labels
Security Fixes
- Prevent email header injection in subject lines — mitigates RCE/SSRF risks (no CVE ID provided)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]