1.0.8.5

blakeblackshear/frigate1.0.8.5Jun 7, 2026by givanz

AI Summary

A security-focused update that introduces sanitization for user bio fields, theme names, and validates URL hosts to prevent IP redirects. The release also adds field templates and fixes various permission and XSS handling issues.

Key Highlights

  • Sanitize save global file and removed editor/* permission
  • Sanitize theme name and user bio on profile save
  • Validate host IP address to avoid private network redirects
  • Fixed sanitizeHTML to prevent more XSS variants
  • Added field templates

New Features

  • Field templates
  • User profile sanitization

Full Release Notes

* Sanitize save global file, removed editor/* permission for editor role, reported by @m1n9yu3 https://github.com/givanz/Vvveb/commit/c8fef41ad8651d348050c513451755ab8882b97e
* Sanitize theme name, reported by @geo-chen https://github.com/givanz/Vvveb/commit/1d76ad52402beeed623a7e386c6796126689a746
* Added sanitize to user bio on profile save, fixed sanitizeHTML to prevent more XSS variants, reported by @JosanGeorge https://github.com/givanz/Vvveb/commit/20a01ef08559ffdc97205edeecde86c8ea27e567
* Check host ip address for validateUrl to avoid ip redirects to private network, reported by @elvinsuleymanov https://github.com/givanz/Vvveb/commit/bd280f5ce136f6da22c873fb1eea9cad8741e623 
* Field templates https://github.com/givanz/Vvveb/commit/57a342b8c96872e084fef7931783243dc74438b1