HedgeDoc 1.10.3

1.10.3

HedgeDoc 1.10.3

Added 1
  • Add config options CMD_SAML_WANT_ASSERTIONS_SIGNED and CMD_SAML_WANT_AUTHN_RESPONSE_SIGNED for SAML auth to accommodate instances not complying with new defaults
Security 1
  • Fix a possible XSS exploit that could be planted via a malicious SVG file upload
Security fixes

This release fixes a security issue of a possible XSS exploit which can be planted via a malicous SVG file upload.

See CVE-2025-32391 for more details

Enhancements
  • Add config options CMD_SAML_WANT_ASSERTIONS_SIGNED and CMD_SAML_WANT_AUTHN_RESPONSE_SIGNED for SAML auth, since some instances didn't comply with the new defaults of @node-saml/passport-saml
View original

Upgraded? How did it go?

Discussion