Skip to content

zwave-js-ui

v11.21.1 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Home Automation
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

control-panel mqtt ui vue zwave zwave-js-ui
+1 more
zwavejs

Affected surfaces

auth deps

Summary

AI summary

Updates 🐛 Bug Fixes, 11.21.1, and 2026-06-23 across a mixed release.

Full changelog

11.21.1 (2026-06-23)

🐛 Bug Fixes

  • confine store paths against the resolved store dir (#4685) (a5dc881), closes pre-#4678 #4678
  • don't return password hash in PUT /api/password response (#4687) (4b0b7d6)
  • prevent symlinks from escaping the store directory (#4678) (592e1b8)
  • refresh broadcast virtual nodes to avoid querying removed nodes (#4688) (8c1981e), closes #4677 #4677
  • ui: separate virtual and physical devices in nodes table (#4673) (3a80ce6), closes #4672
  • write self-signed TLS key/cert with owner-only permissions (#4686) (2f62656)

Security Fixes

  • Removed password hash from `PUT /api/password` response to prevent credential leakage
  • Constrained store paths and prevented symlinks from escaping the resolved store directory

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track zwave-js-ui

Get notified when new releases ship.

Sign up free

About zwave-js-ui

Full featured Z-Wave Control Panel UI and MQTT gateway. Built using Nodejs, and Vue/Vuetify

All releases →

Related context

Beta — feedback welcome: [email protected]