1.0.8.6
n0-computer/iroh1.0.8.6Jun 11, 2026by givanz
AI Summary
This release focuses on security hardening to address vulnerabilities related to private IP redirects, IPv6 bypass, and HTML sanitization, alongside UI updates for the admin panel and page builder.
Key Highlights
- Fixed vulnerability allowing private IP redirects and IPv6 bypass using curl resolve
- Updated admin template and page builder UI
- Fixed sanitizeHTML 'on' attributes sanitization vulnerability
- Added recursive filtering to sanitizeFileName function
New Features
- Admin template update
- Page builder UI changes
- Plugins update
- Fixed tree list expand arrow button click
Full Release Notes
* Use curl resolve to avoid private ip redirect and IPv6 bypass, vulnerability reported by @EvidentObscurity https://github.com/givanz/Vvveb/commit/e27d1ef097a8502c33f8cc94271c948407c5dce3 * Admin template update, page builder UI changes https://github.com/givanz/Vvveb/commit/a4882d42411466ea90b6612933b5d1f70fa7cc83 * Plugins update https://github.com/givanz/Vvveb/commit/513db6d716410d75bed99436bf5ed10384cca100 * Translations edit show server message on error, fixed tree list expand arrow button click https://github.com/givanz/Vvveb/commit/6bc8390957256dd831691f352e8c472fb3c91374 * Fixed sanitizeHTML( 'on' attributes sanitization when attribute has '>', vulnerability reported by @EvidentObscurity https://github.com/givanz/Vvveb/commit/c466e618ad1b94916f56062b7732edb5a336f57d * Added recursive filtering sanitizeFileName(, vulnerability reported by @EvidentObscurity https://github.com/givanz/Vvveb/commit/8c062a047a66d6f04307f8d0e37c34f709a201a9