v1.8.4
OpenSignLabs/OpenSignv1.8.4Apr 9, 2026by lfnovo
AI Summary
Critical security release addressing vulnerabilities for Remote Code Execution, arbitrary file writes, and arbitrary file reads reported by CERT-EU.
Key Highlights
- Bumped ai-prompter to 0.4.0 to use `SandboxedEnvironment` for Jinja2 templates.
- Fixed arbitrary file write via path traversal using `os.path.basename()` and path validation.
- Fixed arbitrary file read via Local File Inclusion by validating paths against the uploads directory.
New Features
- Security hardening via sandboxed template rendering
- Path sanitization for file uploads
- Path validation for file reading
Full Release Notes
## Security Three vulnerabilities reported by CERT-EU Offensive Security Team via coordinated disclosure: - **Remote Code Execution via Server-Side Template Injection** (CVSS 9.2 Critical) - User-created transformation prompts were rendered by an unsandboxed Jinja2 environment, allowing arbitrary Python code execution on the server. Bumped ai-prompter to 0.4.0 which uses `SandboxedEnvironment` for all template rendering. - **Arbitrary file write via path traversal** (CVSS 7.0 High) - File upload did not sanitize filenames, allowing path traversal payloads (e.g., `../../../../tmp/test.txt`) to write files outside the upload directory. Filenames are now sanitized with `os.path.basename()` and resolved paths are validated. - **Arbitrary file read via Local File Inclusion** (CVSS 8.2 High) - The source creation endpoint accepted arbitrary `file_path` values, allowing reading of any file on the container (e.g., `/etc/passwd`, `/proc/self/environ`). File paths are now validated to be within the uploads directory. ### Affected versions All versions up to and including v1.8.3. ### Recommended action Upgrade to v1.8.4 immediately. ### Credit Reported by [CERT-EU](https://cert.europa.eu) Offensive Security Team via coordinated vulnerability disclosure.