Skip to content

v1.7.71 - Security Fixes

Choose a tag to compare

@MacJediWizard MacJediWizard released this 07 Jan 18:00
· 15 commits to main since this release

Security Fixes

This release addresses several medium-severity security issues identified during a security audit.

Backend

  • SVG Sanitization - Added sanitizeSvg() function to remove malicious content from uploaded SVG favicons (script tags, event handlers, javascript: URLs, data: URLs, foreignObject, embed, object, iframe elements)
  • Encryption Key Warning - Added production warning when DATABASE_URL is used for encryption key derivation (recommends setting SESSION_SECRET or AI_ENCRYPTION_KEY)

Frontend

  • Localhost Fallbacks - Fixed hardcoded localhost:3001 fallbacks that would break production deployments. Now uses window.location in production builds.

Other Changes

  • Exported AuthContext for improved test mocking support
  • Updated frontend dependencies

Issues Fixed

  • #176 - SVG favicon XSS vulnerability
  • #177 - Encryption key derivation warning
  • #178 - Hardcoded localhost fallbacks

Full Changelog: v1.7.70...v1.7.71