github Kha-kis/arr-dashboard v2.16.2
v2.16.2 — Security patch release

latest releases: v2.24.1, v2.24.0, v2.23.0...
5 months ago

Security patch release. Closes 8 open code-scanning alerts (1 HIGH-severity Fastify body-schema bypass + 4 medium-severity DOMPurify sanitization issues + 1 GitHub Actions shell-injection vector + 2 transitive hono/postcss vulnerabilities) and 6 Dependabot security advisories. Also adds a small TRaSH Guides feature (migration notices for upstream CF-group restructures) and removes a class of spurious diagnostic warnings. No schema or API breaking changes.

🔒 Fixed

  • Fastify body schema validation bypass via leading-space Content-Type — CVE-2026-33806 (HIGH). Fastify 5.3.2–5.8.4 mishandled Content-Type headers with leading whitespace, allowing requests to skip body schema validation. Bumped to fastify 5.8.5 (#363).
  • DOMPurify sanitization bypasses (4 CVEs) — CVE-2026-41238/41239/41240 + GHSA-39q2-94rc-95cp covered `SAFE_FOR_TEMPLATES` bypass in `RETURN_DOM` mode, `FORBID_TAGS` bypass via function-form `ADD_TAGS`, prototype pollution → XSS via `CUSTOM_ELEMENT_HANDLING` fallback, and `ADD_TAGS` short-circuit evaluation. Bumped to dompurify 3.4.1 (#363).
  • Hono JSX HTML injection in SSR (transitive) — GHSA-458j-xx4x-4375. Updated `pnpm.overrides` to require hono ≥4.12.14 (#369).
  • postcss CVE-2026-41305 (transitive) — Pulled in by `next@16.2.4` which hardcodes the vulnerable version. Added `pnpm.overrides` entry pinning all sub-8.5.10 resolutions to 8.5.10 (#369).
  • GitHub Actions shell-injection vector in release workflow — `${{ github.ref_name }}` used directly inside a `run:` block in `docker-combined.yml` could allow a maliciously crafted tag to inject arbitrary commands. Refactored to use `env:` block pattern (#368).
  • Spurious schema-drift warnings on per-file TRaSH fetch — Per-item validation calls were misreporting sparse upstream fields as drift on every poll. Added `skipFingerprint` option + single batch fingerprint after each loop (#365).

✨ Added

  • TRaSH Guides migration notices — When an upstream CF-group is restructured (e.g., the recent split of `[Optional] Miscellaneous` → `[Unwanted] Unwanted Formats`), the template diff modal now surfaces an informational notice. Notices fire on both live diff and historical-changelog paths, and are suppressed once the migration is complete. Reusable registry mechanism: future restructures only need a registry entry (#364).
  • `trash_regex` declared in TRaSH custom-format schema — Long-standing upstream field on ~20 custom formats now properly typed instead of passing through `z.looseObject()` unmodeled (#367).

🔧 Changed

  • Removed redundant `console.*` calls in TRaSH Guides web surface — 22 calls cleaned up across 13 files. Intentional diagnostic calls preserved (#366).
  • Lint hygiene: 9 unused-imports warnings cleared — `catch (err)` parameters underscore-prefixed; ESLint config extended with `caughtErrors: "all"` + `caughtErrorsIgnorePattern: "^_"` (#371).

📦 Dependencies

  • Production (23 packages) — `knip` 6.4→6.7, `@prisma/*` 7.7→7.8, `@tanstack/react-query` 5.99→5.100.5, `next` 16.2.3→16.2.4, `lucide-react` 1.8→1.11, `react-hook-form` 7.72→7.74, `postcss` / `tailwindcss` 4.2.2→4.2.4, others (#363).
  • Dev (3 packages) — `@biomejs/biome` 2.4.11→2.4.13, `typescript`, `vitest` (#362).
  • Trivy scan timeout 5m → 20m — Default 5-minute timeout consistently failed analyzing `@prisma/config@7.8.0` after the Prisma 7.8 bump. Applied to both `docker-dev.yml` and `docker-combined.yml` (#370).

Full Changelog: v2.16.1...v2.16.2

Don't miss a new arr-dashboard release

NewReleases is sending notifications on new releases.