Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Grimmory 3.5.0: Drei Sicherheitslücken behoben, Tap-Navigation im epub-Reader
Grimmory 3.5.0 behebt drei Sicherheitslücken (unberechtigter Zugriff auf Servereinstellungen über /api/v1/settings, Uploads in nicht zugängliche Bibliotheken und CPU-/Thread-Erschöpfung durch manipulierte epub-Dateien) und ergänzt einen Metadata-Provider-Controller in der API sowie Tap-Navigation im epub-Reader für Mobilgeräte.
3.5.0 (2026-09-20)
This minor release primarily fixes three identified security issues in Grimmory:
- The
/api/v1/settingsendpoint allowed any user to access sensitive server settings. (GHSA-x6vg-344c-qrmv) - The upload feature did not restrict users to only uploading into libraries they had access to. (GHSA-7f4w-5hc7-j96r)
- An appropriately crafted epub could have lead to CPU / web server request thread exhaustion. (GHSA-mx77-3cq4-g227)
Changelog
Full Changelog: https://github.com/grimmory-tools/grimmory/compare/v3.4.1...v3.5.0
Features
- api: add metadata provider controller (#2673) (
402e89b) - reader: add epub reader tap navigation for mobile (#1909) (
c8a1a59)
Bug Fixes
- api: add library access check to uploads (#2648) (
2d7a3e9) …