This release includes 4 security fixes for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
ReleasePort's take
Moderate signalRelease v2.24.0 patches critical security flaws in authentication flows and hardens the platform against brute‑force attacks.
Why it matters: Fixes high‑severity path traversal (severity 90) and password reset poisoning (severity 90) vulnerabilities affecting API/authentication endpoints and the password reset flow, plus mitigates 2FA brute‑force attempts (severity 85).
Summary
AI summaryUpdates https://plugins.typemill.net/plantuml, https://plugins.typemill.net/askthedocs, and Improvement across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes path traversal vulnerability Fixes path traversal vulnerability Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Security | Critical |
Fixes password reset poisoning vulnerability Fixes password reset poisoning vulnerability Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Security | High |
Mitigates 2FA brute-force attacks Mitigates 2FA brute-force attacks Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Security | High |
Ensures unique user enforcement Ensures unique user enforcement Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Medium |
Adds AI‑assisted help feature in kixote Adds AI‑assisted help feature in kixote Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Medium |
Adds system tab for customizing authentication pages on login Adds system tab for customizing authentication pages on login Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Adds PlantUML plugin support Adds PlantUML plugin support Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Adds "Ask the doc" chatbot plugin Adds "Ask the doc" chatbot plugin Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Bugfix | Medium |
Removes AI elements from interface when no AI service is active Removes AI elements from interface when no AI service is active Source: llm_adapter@2026-06-14 Confidence: high |
— |
Full changelog
- New Feature: Integration of an ai assisted help feature in kixote.
- New Feature: New system tab for login to customize authentication pages.
- New Plugin: Use PlantUML with Typemill (user contribution).
- New Plugin: Ask the doc chatbot for your Typemill website.
- Improvement: All ai elements are removed from interface if no AI service is activated.
- Security fix for path traversal.
- Security fix for password reset poisoning.
- Security fix for 2fa brute force.
- Security fix for unique user.
Security Fixes
- Path traversal vulnerability fixed
- Password reset poisoning vulnerability fixed
- 2FA brute force attack protection implemented
- Unique user enforcement security fix applied
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About typemill
Typemill is a flat-file CMS based on Markdown and designed for informational websites like documentation, manuals, and handbooks.
Beta — feedback welcome: [email protected]