Skip to content

typemill

v2.24.0 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

Published 1mo Documentation
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

cms docs documentation documentation-tool ebooks epub-generation
+11 more
flat-file handbooks helpauthoring manuals markdown pdf-generation publication self-hosted technical-writing userguides websites

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

Release v2.24.0 patches critical security flaws in authentication flows and hardens the platform against brute‑force attacks.

Why it matters: Fixes high‑severity path traversal (severity 90) and password reset poisoning (severity 90) vulnerabilities affecting API/authentication endpoints and the password reset flow, plus mitigates 2FA brute‑force attempts (severity 85).

Summary

AI summary

Updates https://plugins.typemill.net/plantuml, https://plugins.typemill.net/askthedocs, and Improvement across a mixed release.

Changes in this release

Security Critical

Fixes path traversal vulnerability

Fixes path traversal vulnerability

Source: llm_adapter@2026-06-14

Confidence: high

Security Critical

Fixes password reset poisoning vulnerability

Fixes password reset poisoning vulnerability

Source: llm_adapter@2026-06-14

Confidence: high

Security High

Mitigates 2FA brute-force attacks

Mitigates 2FA brute-force attacks

Source: llm_adapter@2026-06-14

Confidence: high

Security High

Ensures unique user enforcement

Ensures unique user enforcement

Source: llm_adapter@2026-06-14

Confidence: high

Feature Medium

Adds AI‑assisted help feature in kixote

Adds AI‑assisted help feature in kixote

Source: llm_adapter@2026-06-14

Confidence: high

Feature Medium

Adds system tab for customizing authentication pages on login

Adds system tab for customizing authentication pages on login

Source: llm_adapter@2026-06-14

Confidence: high

Feature Low

Adds PlantUML plugin support

Adds PlantUML plugin support

Source: llm_adapter@2026-06-14

Confidence: high

Feature Low

Adds "Ask the doc" chatbot plugin

Adds "Ask the doc" chatbot plugin

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Removes AI elements from interface when no AI service is active

Removes AI elements from interface when no AI service is active

Source: llm_adapter@2026-06-14

Confidence: high

Full changelog
  • New Feature: Integration of an ai assisted help feature in kixote.
  • New Feature: New system tab for login to customize authentication pages.
  • New Plugin: Use PlantUML with Typemill (user contribution).
  • New Plugin: Ask the doc chatbot for your Typemill website.
  • Improvement: All ai elements are removed from interface if no AI service is activated.
  • Security fix for path traversal.
  • Security fix for password reset poisoning.
  • Security fix for 2fa brute force.
  • Security fix for unique user.

Security Fixes

  • Path traversal vulnerability fixed
  • Password reset poisoning vulnerability fixed
  • 2FA brute force attack protection implemented
  • Unique user enforcement security fix applied

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track typemill

Get notified when new releases ship.

Sign up free

About typemill

Typemill is a flat-file CMS based on Markdown and designed for informational websites like documentation, manuals, and handbooks.

All releases →

Related context

Beta — feedback welcome: [email protected]