v4.5.0.7
VoiceBlender/voiceblenderv4.5.0.7Jun 22, 2026by sid-swirl
AI Summary
This is a security patch release for the SWIRL Community edition. It addresses privilege escalation vulnerabilities in OIDC sign-in and cross-user token fallback issues in Microsoft 365 connectors.
Key Highlights
- Security Patch: OIDC privilege escalation fixed (no longer provisions superuser)
- Security Patch: Cross-user Microsoft token fallback fixed (strict user scoping)
- No schema or dependency changes
Full Release Notes
SWIRL Community 4.5.0.7 — Security Patch Fixes [#1941](https://github.com/swirlai/swirl-search/issues/1941): * OIDC privilege escalation: sign-in no longer provisions superuser/staff accounts, and no longer sets a shared hardcoded password. * Cross-user Microsoft token fallback: M365 token lookup is now strictly scoped to the requesting user; removed the fallback that could use another user's credentials. No schema or dependency changes. Upgrade recommended for any deployment using OIDC sign-in or M365 connectors.