This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 1mo
Home Automation
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
control-panel
mqtt
ui
vue
zwave
zwave-js-ui
+1 more
zwavejs
Affected surfaces
auth
deps
Summary
AI summaryUpdates 🐛 Bug Fixes, 11.21.1, and 2026-06-23 across a mixed release.
Full changelog
11.21.1 (2026-06-23)
🐛 Bug Fixes
- confine store paths against the resolved store dir (#4685) (a5dc881), closes pre-#4678 #4678
- don't return password hash in
PUT /api/passwordresponse (#4687) (4b0b7d6) - prevent symlinks from escaping the store directory (#4678) (592e1b8)
- refresh broadcast virtual nodes to avoid querying removed nodes (#4688) (8c1981e), closes #4677 #4677
- ui: separate virtual and physical devices in nodes table (#4673) (3a80ce6), closes #4672
- write self-signed TLS key/cert with owner-only permissions (#4686) (2f62656)
Security Fixes
- Removed password hash from `PUT /api/password` response to prevent credential leakage
- Constrained store paths and prevented symlinks from escaping the resolved store directory
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About zwave-js-ui
Full featured Z-Wave Control Panel UI and MQTT gateway. Built using Nodejs, and Vue/Vuetify
Related context
Related tools
Beta — feedback welcome: [email protected]