v1.7.71 - Security Fixes
Security Fixes
This release addresses several medium-severity security issues identified during a security audit.
Backend
- SVG Sanitization - Added
sanitizeSvg()function to remove malicious content from uploaded SVG favicons (script tags, event handlers, javascript: URLs, data: URLs, foreignObject, embed, object, iframe elements) - Encryption Key Warning - Added production warning when
DATABASE_URLis used for encryption key derivation (recommends settingSESSION_SECRETorAI_ENCRYPTION_KEY)
Frontend
- Localhost Fallbacks - Fixed hardcoded
localhost:3001fallbacks that would break production deployments. Now useswindow.locationin production builds.
Other Changes
- Exported
AuthContextfor improved test mocking support - Updated frontend dependencies
Issues Fixed
- #176 - SVG favicon XSS vulnerability
- #177 - Encryption key derivation warning
- #178 - Hardcoded localhost fallbacks
Full Changelog: v1.7.70...v1.7.71