Skip to content

appsmith

Developer Productivity

An open‑source low‑code platform for rapidly building, deploying and maintaining custom internal applications like dashboards, admin panels and automation tools

TypeScript Latest v2.1 · 5d ago Security brief →

Features

  • Low‑code visual builder for creating custom web apps quickly
  • Supports multiple deployment options: cloud SaaS, Docker containers, Kubernetes clusters, and AWS AMI
  • Extensive documentation, tutorials and community resources for onboarding and support

Recent releases

View all 7 releases →
Review required
v2.1 Breaking risk
RCE / SSRF Dependencies Auth +1 more

SSRF filter + Caddy + Supervisord

Review required
v2.0 Breaking risk
RCE / SSRF Auth Dependencies +1 more

Mandatory v1.99 intermediate upgrade

v1.99 Breaking risk
Security fixes
  • CVE-2025-70952 (critical)
  • CVE-2026-33937 (handlebars upgrade)
  • CVE-2026-22732 (Spring Security HTTP headers)
Notable features
  • AQL injection prevention in ArangoDB plugin
  • Reflected XSS prevention in ManualUpgrades
v1.98 Security relevant
Security fixes
  • Enforced edit permissions for application snapshot deletion (GHSA-g2hc-wmw2-32jr)
  • Prevented unauthenticated disclosure of instance metadata (APP-14994)
  • Prevented SQL injection in UQI filter service projection and sortBy columns
Notable features
  • TLS (SSL mode) support for Redis datasource
v1.97 New feature
Security fixes
  • Prevented open redirects in login and OAuth2 redirect flows
Notable features
  • On-the-fly response compression in Caddy
  • Favorite Applications (V2)
  • New TableWidgetV2 style properties (headerRowColor, oddRowColor, evenRowColor)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
39,948
Forks
4,587
Languages
TypeScript Java JavaScript

Install & Platforms

Install via
docker

Community & Support

Open source alternatives

Beta — feedback welcome: [email protected]