v3.2.1

mikeqzy/3dgs-avatar-releasev3.2.1May 15, 2026by cnkk

AI Summary

This patch release addresses a critical security vulnerability (CVE-2026-8467) by removing the exposed HTTP '/storybook' endpoint, which previously allowed for remote code execution. It is a mandatory update for all affected versions of Plausible Community Edition.

Key Highlights

  • Fixes CVE-2026-8467 / GHSA-55hg-8qxv-qj4p (Remote Code Execution)
  • Removes HTTP '/storybook' endpoint to prevent RCE
  • Applies to versions v3.0.0 through v3.2.0

Breaking Changes

  • Removal of the HTTP '/storybook' endpoint

Full Release Notes

# Security related update

This patch release **fixes a security vulnerability**[`CVE-2026-8467` / `GHSA-55hg-8qxv-qj4p`](https://github.com/phenixdigital/phoenix_storybook/security/advisories/GHSA-55hg-8qxv-qj4p) affecting the following versions of Plausible Community Edition (image: ghcr.io/plausible/community-edition):
Tags:
- v3.2
- v3.2.0
- v3
- v3.2.0-rc.0
- v3.1
- v3.1.0
- v3.1.0-rc.1
- v3.1.0-rc.0
- v3.0.1
- v3.0
- v3.0.0
- v3.0.0-rc.6
- v3.0.0-rc.5
- v3.0.0-rc.4
- v3.0.0-rc.3
- v3.0.0-rc.2
- v3.0.0-rc.1
- v3.0.0-rc.0

The affected versions expose a `HTTP "/storybook"` endpoint which, under certain conditions, allows remote code execution with privileges of system user running the application.

This release v3.2.1 of Plausible Community Edition completely removes that endpoint.

## Who is affected?

All deployments of Plausible Community Edition running the following versions:

- v3.2
- v3.2.0
- v3
- v3.2.0-rc.0
- v3.1
- v3.1.0
- v3.1.0-rc.1
- v3.1.0-rc.0
- v3.0.1
- v3.0
- v3.0.0
- v3.0.0-rc.6
- v3.0.0-rc.5
- v3.0.0-rc.4
- v3.0.0-rc.3
- v3.0.0-rc.2
- v3.0.0-rc.1
- v3.0.0-rc.0

where `HTTP "/storybook"` endpoint is exposed to a public or other untrusted network.

## Mitigation

All affected versions of Plausible Community Edition should be updated to v3.2.1 as soon as possible.

As an immediate mitigation, it is recommended to block access to HTTP "/storybook" endpoint in your reverse proxy configuration or via other applicable means.

## Changes in this release

- Remove `HTTP "/storybook"` endpoint along with the associated logic

No other changes are included in this release.