Skip to content

v1.7.28

Compare
Choose a tag to compare
@RiotRobot RiotRobot released this 17 May 12:59
· 3185 commits to develop since this release
v1.7.28

Full Changelog

Security notice

Element Web 1.7.28 fixes (by upgrading to matrix-react-sdk 3.21.0) a low
severity issue (GHSA-8796-gc9j-63rv) related to file upload. When uploading a
file, the local file preview can lead to execution of scripts embedded in the
uploaded file, but only after several user interactions to open the preview in
a separate tab. This only impacts the local user while in the process of
uploading. It cannot be exploited remotely or by other users. Thanks to
Muhammad Zaid Ghifari for responsibly disclosing
this via Matrix's Security Disclosure Policy.

All changes

  • Upgrade to React SDK 3.21.0 and JS SDK 11.0.0