1.10.3
HedgeDoc 1.10.3
Added 1
- Add config options CMD_SAML_WANT_ASSERTIONS_SIGNED and CMD_SAML_WANT_AUTHN_RESPONSE_SIGNED for SAML auth to accommodate instances not complying with new defaults
Security 1
- Fix a possible XSS exploit that could be planted via a malicious SVG file upload
Security fixes
This release fixes a security issue of a possible XSS exploit which can be planted via a malicous SVG file upload.
See CVE-2025-32391 for more details
Enhancements
- Add config options
CMD_SAML_WANT_ASSERTIONS_SIGNEDandCMD_SAML_WANT_AUTHN_RESPONSE_SIGNEDfor SAML auth, since some instances didn't comply with the new defaults of@node-saml/passport-saml