KeystoneJS
Developer ProductivityA developer‑focused, extensible content management system that generates a GraphQL API and admin UI from your schema definition.
Features
- Generates a powerful GraphQL API automatically from your data schema
- Provides a beautiful, self‑hosted management UI for content and data
- Zero boilerplate – start with the `create-keystone-app` CLI to scaffold projects instantly
Recent releases
View all 2 releases →- CVE-2026-33326 — {field}.isFilterable access control could be bypassed in `findMany` queries by passing a `cursor`, allowing existence confirmation of protected records.
Full changelog
The following packages have been updated
@keystone-6/[email protected]
Bug Fixes
[core]FixisFilterablebypass viacursorparameter infindManyquery (#9790) @n0wsh
:rotating_light: Security Updates
We have identified and fixed 1 security vulnerability
CVE-2026-33326- {field}.isFilterable access control could be bypassed infindManyqueries by passing acursor. This could be used to confirm the existence of records by protected field values.
:eyes: Review
See https://github.com/keystonejs/keystone/compare/2025-05-06...2026-03-19 to compare with our previous release.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.