3.8.12
Bugfix
- [security] The profile self-update form now ignores client-supplied
groupsandaccessfields, closing a privilege-escalation gap where a logged-in user could grant themselves super-admin if an administrator had added those fields to the registration allowlist (GHSA-h33v-82r9-v8pm). Thanks to zx (Jace) for the report.