Skip to content

Ghostwriter v6.3.1

Choose a tag to compare

@chrismaddalena chrismaddalena released this 18 Apr 00:55
· 678 commits to master since this release
b5d2c18

Summary

This release fixes some bugs and cleans up some issues with edge cases to improve reliability in various areas. It also introduces improved control over evidence width and alignment for the global report configuration and individual report templates.

CHANGELOG

[6.3.1] - 17 April 2026

Added

  • Control Over Max File Size: Added GHOSTWRITER_MAX_FILE_SIZE to manage the maximum file size for uploads
    • This new value defaults to 10MB and can be controlled via Ghostwriter CLI
    • The value limits the size of evidence and terminal recording uploads and downloads
    • These files load into memory for certain actions (e.g., recording playback, base64-encoding) and this guards against extremely large files using excessive system resources

Changed

  • Better Control Over Image Evidence Display: Global and template values for controlling evidence width and alignment
    • Previously, you could only set image width on a template and images were always center aligned
    • Width and alignment are now global report configuration values and template configuration values
    • Ghostwriter uses the global value unless a template has its own values set
    • If no width value is set inn either location, Ghostwriter defaults to 6.5" (full width for a default Word document)
  • Offloaded alignment of code blocks for text evidence to the CodeBlock style in the template
    • Previously, Ghostwriter always set code blocks to be left aligned
    • Ghostwriter will now set left alignment only if the CodeBlock style is missing
    • The CodeBlock style's alignment configuration will determine the block's alignment
  • The MOTD banner's banner_link field is now a URL field and applies URL validation
  • Set a max upload size for evidence as a guard against very large uploads
  • The collaborative editor's color picker now validates color values
  • Added sanitization to strip some characters from the export filenames for operation logs for safer exports
  • The start script for Django will now run the migrate_totp_device to migrate MFA records set up prior to v6.1
  • Restricted links in the collaborative editor to valid URL schemes (e.g., http, https, mailto)
  • Changed the to_datetime filter to not require a format string
    • The filter will now automatically match a format string with Django's DATE_INPUT_FORMATS when a format string is not provided
  • Adjusted tag autocomplete to only offer tags already applied to objects to which the user has access

Fixed

  • Fixed MFA recovery codes not displaying when they should
  • Fixed an issue that could occur when rendering a report with a table that was missing table tags
  • Fixed a report generation endpoint that did not properly redirect when the report did not exist
  • Fixed sanitizing the identifier on log entries
  • Fixed an issue that could occur with filter_bhe_findings_by_domain when domain SID or BloodHound environment_id were empty
  • Fixed an edge case where a single contact on a client or project could be flagged as not the primary contact
  • Fixed an issue that prevented report archives from being created
  • Fixed the table caption "Set Bookmark" command in the editor being available when it should not be

Security

  • Restored the HttpOnly flag to cookies
  • Restricted collab-server inspector to localhost for development environments