PrivateBin
Developer ProductivityA minimalist, open source online pastebin where the server has zero knowledge of pasted data. Data is encrypted/decrypted in the browser using 256 bits AES.
Features
- Zero‑knowledge paste storage with client‑side AES‑256‑GCM encryption
- Optional password protection for additional confidentiality
- Configurable expiration options (including "burn after reading")
- Supports Markdown formatting and syntax highlighting
- Allows file uploads, image preview, and QR code generation
Recent releases
View all 9 releases →
2.0.4
Breaking risk
Breaking changes
- Removed obsolete X-XSS-Protection header
Notable features
- Added Swedish and Persian translations
Full changelog
- ADDED: Translations for Swedish & Persian
- CHANGED: Deduplicate JSON error message translations
- CHANGED: Refactored translation of exception messages
- CHANGED: Upgrading libraries to: DOMpurify 3.4.1, ip-lib 1.22.0, polyfill-php80 1.34.0 & zlib 1.3.2
- CHANGED: Remove obsolete X-XSS-Protection header (#1825)
- FIXED: Some exceptions not getting translated
- FIXED: Attachment disappears after a "paste" in the message area (#1731)
- FIXED: The content format is not reset when creating a new document (#1707)
1.7.9
Security relevant
Security fixes
- CVE-2025-64714: Template-switching feature path traversal for arbitrary local file inclusion
- CVE-2025-64711: Malicious filename enabling self-XSS and HTML injection
- CVE-2025-62796: Missing HTML sanitisation enabling persistent XSS in attachment filenames
2.0.3
Security relevant
Security fixes
- Arbitrary PHP file inclusion via template switching (CVE-2025-64714)
- Malicious filename XSS/HTML injection (CVE-2025-64711)
2.0.2
Security relevant
Security fixes
- Unsanitized filename in attachment size hint (CVE-2025-62796)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.