Skip to content

Conversation

@bobvandevijver
Copy link
Member

@bobvandevijver bobvandevijver commented Aug 18, 2025

By default Bolt offers a lot of file extensions, which can result in XSS (for example, uploading HTML with JS content). This has been reported anonymously, and we have decided it is best to limit the default and add a note about this in the settings file. That is what this PR does.

A change to existing installations was explicitly not added.

@bobvandevijver bobvandevijver changed the base branch from main to 5.2 August 18, 2025 13:51
@bobvandevijver bobvandevijver marked this pull request as ready for review August 18, 2025 13:51
@bobvandevijver bobvandevijver merged commit dcf6d36 into 5.2 Aug 18, 2025
42 checks passed
@bobvandevijver bobvandevijver deleted the limit-file-types branch August 18, 2025 14:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants