Skip to content

papra

Productivity & Wikis

The minimalistic document archiving platform.

TypeScript Latest @papra/[email protected] · 14d ago Security brief →

Features

  • Document management with upload, storage, and organization
  • Full‑text search with advanced filters
  • Self‑hosting via Docker (lightweight <200 MB image)

Recent releases

View all 13 releases →
Upgrade now
@papra/[email protected] Breaking risk
Auth RBAC Dependencies

Tag scope + webhook redirects + upload limit

@papra/[email protected] Breaking risk
Breaking changes
  • Webhooks pointing to private or reserved IP addresses are now blocked unless explicitly listed in WEBHOOK_URL_ALLOWED_HOSTNAMES config
Security fixes
  • GHSA-cjw7-qg95-58mq: SSRF protection for webhook URLs
  • GHSA-866c-mc22-wvv5: Removed unsafe expiresAt placeholder fields in API key creation endpoint
  • GHSA-6f8x-2rc9-vgh4: Sanitized user names in email content to prevent XSS/HTML injection
Notable features
  • SSRF protection for webhook URLs with configurable allowlist via WEBHOOK_URL_ALLOWED_HOSTNAMES
  • Improved error handling returning 409 status code for duplicate tags instead of 400 or 500 errors

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
4,643
Forks
231
Languages
TypeScript MDX Astro
Downloads/week
179 ↑373%
NPM Maintainers
1
Contributors
30
TypeScript
Types included ✓

Install & Platforms

Install via
docker
Platforms
linux arm64

Beta — feedback welcome: [email protected]