3.45.11 (2026-08-01)
Bug Fixes
- security: block guest access to hidden/client-only photos across bulk + secure routes (stable) (#940) (34a7b1c)
- security: bump sanitize-html to 2.17.5 (CVE-2026-53606) (stable) (#938) (7419c68)
- security: close authorization/ownership gaps (token scope, mass-assignment, category hero, project docs) (stable) (#944) (2462ba6)
- security: resolve DNS before vetting external hostnames (SSRF cluster) (stable) (#942) (90275f8)
- uploads: prevent cross-photo contamination from filename collisions and non-atomic writes (#931) (stable) (#934) (fc99e2b)