RCE prevention + icon change + UI exec conditions
Release history
OliveTin releases
OliveTin gives safe and simple access to predefined shell commands from a web interface.
All releases
17 shown
- GHSA-228v-wc5r-j8m7 - Unauthorized action output via EventStream
- GHSA-xx6g-43w2-9g6g - Email argument log injection
- GHSA-364q-w7vh-vhpc - Unsafe UniqueTrackingId parsing enabling file writes
- Actions unauthorized for viewing no longer returned
- GHSA-g962-2j28-3cg9 - JWT audience validation bypass
- GHSA-fwhj-785h-43hh - Crash on invalid bindings
- GHSA-gq2m-77hf-vwgh - Session fixation on logout
- GHSA-4fqm-6fmh-82mq - Authentication bypass in KillAction
- GHSA-45m3-398w-m2m9 - Remote crash in OAuth2
- Policy to show/hide version number
- Clickable links in action output
- GHSA-pc8g-78pf-4xrp - Resource exhaustion via password hash
- GHSA-6f34-72v5-3cwv - Insecure cookie handling
- IDOR on ExecutionStatus API
- CVE-2026-27626 / GHSA-49gm-hh7w-wfvf - Critical RCE via password arguments
- Navigate-on-start icon configuration
- Template parsing for env in password fields
Fixed release trigger pipeline configuration issue that was blocking automated releases.
Restored environment variable support that was accidentally removed, enabling users to reference environment variables in action configurations.
Fixed calendar scheduling issues from version 2k, prevented crashes in execOnCalendarFile by safely handling nil timers.
Fixed process group timeout handling to properly kill child processes when actions exceed time limits, preventing zombie processes.
- Constant-time comparison for Basic auth and webhook verification
- Enable/disable actions based on rules
- Webhook support for action triggers
- Theme selector and calendar log view
- Constant-time comparison for Basic auth verification
- Enable/disable actions based on rules
- Webhook support for action execution
- Calendar view for logs