Skip to content

2.11.1 - Security fix for request YAML loading

Choose a tag to compare

@darrenburns darrenburns released this 05 Oct 14:12
· 5 commits to main since this release
53db4d8

Security

Posting 2.11.1 fixes a code-execution vulnerability. Upgrading is recommended for everyone.

Older versions loaded request files (.posting.yaml) with a YAML loader that constructs Python objects. A crafted request file could run arbitrary commands as soon as Posting loaded the collection containing it, for example after cloning a repository or opening a shared collection.

  • Request files are now loaded with YAML's safe loader, and Python object tags are rejected (reported in #348 and #383).
  • Theme files are now loaded with the safe loader too.

Request files that Posting saved itself are unaffected and load as before.

Upgrade: uv tool upgrade posting, or pipx upgrade posting