This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
ReleasePort's take
Moderate signalVersion v2.25.0 of typemill adds configurable AI request timeouts and reasoning‑effort controls while fixing a critical 2FA brute‑force bypass vulnerability.
Why it matters: The release patches a high‑severity (severity 95) 2FA brute‑force protection bypass; operators should apply the update immediately to prevent authentication abuse.
Summary
AI summarySecurity fix patches a 2FA brute‑force bypass and adds configurable AI request timeout, reasoning‑effort control, and an onExportHtmlLoaded event.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes 2FA brute-force protection bypass vulnerability Fixes 2FA brute-force protection bypass vulnerability Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Adds configurable AI request timeout Adds configurable AI request timeout Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Adds reasoning-effort control for OpenAI-compatible models Adds reasoning-effort control for OpenAI-compatible models Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Adds new event onExportHtmlLoaded to export static assets for ebooks Adds new event onExportHtmlLoaded to export static assets for ebooks Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Improves 2FA authcode input by simplifying to one form Improves 2FA authcode input by simplifying to one form Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Improves validation for multi-project base settings Improves validation for multi-project base settings Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
- Feature: Configurable AI request timeout
- Feature: Reasoning-effort control for OpenAI-compatible models
- Feature: New event onExportHtmlLoaded to export static assets for ebooks
- Improvement: Simplified 2FA authcode input with one input form
- Improvement: validation for multi-project base settings
- Security Fix for 2FA brute-force protection bypass
Security Fixes
- Fixes bypass of 2FA brute‑force protection
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About typemill
Typemill is a flat-file CMS based on Markdown and designed for informational websites like documentation, manuals, and handbooks.
Beta — feedback welcome: [email protected]