1.0.8.5

ShenhanQian/GaussianAvatars1.0.8.5Jun 7, 2026by givanz

AI Summary

A security-focused release that hardens user input handling by sanitizing global files, themes, and user bios to prevent XSS attacks, while also adding field templates functionality.

Key Highlights

  • Sanitized global file saving and theme names to prevent potential issues
  • Enhanced XSS protection by sanitizing user bio and updating `sanitizeHTML` methods
  • Improved URL validation by checking host IP addresses to block private network redirects
  • Added field templates functionality

New Features

  • Field templates

Full Release Notes

* Sanitize save global file, removed editor/* permission for editor role, reported by @m1n9yu3 https://github.com/givanz/Vvveb/commit/c8fef41ad8651d348050c513451755ab8882b97e
* Sanitize theme name, reported by @geo-chen https://github.com/givanz/Vvveb/commit/1d76ad52402beeed623a7e386c6796126689a746
* Added sanitize to user bio on profile save, fixed sanitizeHTML to prevent more XSS variants, reported by @JosanGeorge https://github.com/givanz/Vvveb/commit/20a01ef08559ffdc97205edeecde86c8ea27e567
* Check host ip address for validateUrl to avoid ip redirects to private network, reported by @elvinsuleymanov https://github.com/givanz/Vvveb/commit/bd280f5ce136f6da22c873fb1eea9cad8741e623 
* Field templates https://github.com/givanz/Vvveb/commit/57a342b8c96872e084fef7931783243dc74438b1