Skip to content

zitadel

v3.4.13 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

2fa authentication authorization fido2 fips-140-3 identity
+11 more
login mfa multitenancy oauth2 oidc openid-connect passkeys saml scim sso user

Affected surfaces

rce_ssrf

Summary

AI summary

Fixed a bug that prevented unauthorized disk access through the require function in actions.

Changes in this release

Bugfix High

prevents disk access via require in actions module

prevents disk access via require in actions module

Source: llm_adapter@2026-07-17

Confidence: high

Full changelog

3.4.13 (2026-07-17)

Bug Fixes

  • actions: prevent disk access via require (e28d6bc)

Security Fixes

  • Prevented unauthorized disk access via require in actions (potential arbitrary file read/write vulnerability).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track zitadel

Get notified when new releases ship.

Sign up free

About zitadel

ZITADEL - Identity infrastructure, simplified for you.

All releases →

Beta — feedback welcome: [email protected]