Skip to content

v1.3.1: Security Patch for adm-zip CVE-2026-39244

Choose a tag to compare

@bshea-1 bshea-1 released this 07 Sep 01:46
· 17 commits to main since this release

Routed v1.3.1 Release Notes

Security Patch

  • adm-zip Vulnerability Fix (CVE-2026-39244): Added an explicit package override locking adm-zip to >=0.6.0, preventing unvalidated ZIP central directory header allocations and potential DoS crashes in transitive dependencies (onnxruntime-node). Special thanks to @begininvoke for the report in #1!

Download Standalone Installers:

  • Windows: RoutedSetup.exe (or run Install-Routed.ps1 in PowerShell)
  • macOS: RoutedSetup.pkg (Apple Installer) or RoutedSetup.dmg
  • Linux: RoutedSetup.deb (Debian/Ubuntu) or routed-linux-x64.tar.gz