# OpenRGB release_candidate_1.0rc3.1 — OpenRGB Release Candidate 1.0rc3 Hotfix 1 - Product: OpenRGB (https://whatsnew.fyi/product/openrgb) - Vendor: OpenRGB - Date: 2026-08-23 - Version: release_candidate_1.0rc3.1 - Original notes: https://codeberg.org/OpenRGB/OpenRGB/releases/tag/release_candidate_1.0rc3.1 - Permalink: https://whatsnew.fyi/product/openrgb/releases/release-candidate-1.0rc3.1 - Labels: Platforms: Desktop What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Add filename sanitization to profile save, load, and delete requests - **security** — Add limit to the maximum packet size accepted by the server and client - **security** — Run the background service to localhost only - **security** — Add hardening to the included systemd service file This is a small hotfix release for OpenRGB Release Candidate 1.0rc3 that addresses some security issues. It adds filename sanitization to profile save, load, and delete requests, a limit to the maximum packet size accepted by the server and client, and runs the background service to localhost only. It also adds some hardening to the included systemd service file. This addresses a situation where a malicious client could escape the OpenRGB configuration directory when performing a profile save or delete operation.