# CyberChef v11.4.0 - Product: CyberChef (https://whatsnew.fyi/product/cyberchef) - Vendor: gchq - Date: 2026-08-18 - Version: v11.4.0 - Original notes: https://github.com/gchq/CyberChef/releases/tag/v11.4.0 - Permalink: https://whatsnew.fyi/product/cyberchef/releases/v11.4.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Patch XSS in Regular expression module - **added** — Add XPRESS (MS-XCA) decompression operations - **added** — Add support for Node 26 - **added** — Add Modular Exponentiation operation - **fixed** — Use js-yaml for both JSON to YAML and YAML to JSON - **fixed** — Replace shasum / sha256sum / sed calls with node built-ins - **fixed** — Stop Parse QR Code from participating in Magic - **fixed** — Restrict A1Z26 Magic checks to valid ranges - **changed** — Extend automated ingredient validation to include argSelector ingredients This release includes a security fix - Security: patch XSS in Regular expression module [@Ne0re0] - chore (deps): bump @codemirror/view from 6.43.8 to 6.43.9 in the patch-updates group | [#2731] - chore (deps): bump @codemirror/commands from 6.10.4 to 6.11.0 in the minor-updates group | [#2732] - Add XPRESS (MS-XCA) decompression operations [@MP-GOWTHAM] | [#2722] - Feat/node 26 support [@alleria173] | [#2699] - chore(root): update allowlist [@evenstensberg] | [#2713] - chore (deps): bump the patch-updates group across 1 directory with 7 updates | [#2730] - chore (deps): bump the minor-updates group across 1 directory with 9 updates | [#2729] - chore (deps): bump docker/login-action from 4.5.2 to 4.6.0 in the actions-dependencies group | [#2716] - chore (deps): bump node from `a0b9bf0` to `d32cdf6` in the docker-dependencies group | [#2723] - docs(root): improve docs a bit [@evenstensberg] | [#2718] - fix: use js-yaml for both JSON to YAML and YAML to JSON [@bartvanandel] | [#2710] - chore (deps): bump the patch-updates group across 1 directory with 6 updates | [#2712] - chore (deps): bump the minor-updates group across 1 directory with 3 updates | [#2705] - chore (deps): bump the actions-dependencies group with 2 updates | [#2703] - fix: replace `shasum` / `sha256sum` / `sed` calls with node built-ins [@bartvanandel] | [#2019] - chore (deps): bump fast-uri from 3.1.4 to 3.1.5 | [#2709] - chore (deps): bump ip-address from 10.2.0 to 10.4.0 | [#2708] - fix: stop Parse QR Code from participating in Magic (#2610) [@Sanjays2402] | [#2613] - Restrict A1Z26 Magic checks to valid ranges [@vetrovk] | [#2644] - feat: Extend automated ingredient validation to include argSelector ingredients (#2641) [@mansiverma897993] | [#2643] - Add Modular Exponentiation operation [@p-leriche] | [#2149] - Add npm allowScripts policy for npm v12 [@zainnadeem786] | [#2682] - chore (deps): bump assorted vulnerable dependencies [@GCHQDeveloper581] | [#2689] - chore (deps): bump shell-quote from 1.8.4 to 1.10.0 | [#2690] - chore (deps): bump the patch-updates group across 1 directory with 9 updates | [#2686] - chore (deps): bump the actions-dependencies group across 1 directory with 2 updates | [#2685] - chore (deps): bump nginxinc/nginx-unprivileged from `fd3314e` to `44e3633` in the docker-dependencies group | [#2684]