This release patches a security issue. An attacker can execute a XSS via uploading an attachment and getting a user to preview it.
Thanks to @v4nsh0x for their security report.
Changes
Changed
- bump deps
Fixed
- security vulnerability GHSA-2cw9-vm9g-7qqg; XSS via attachment
Full Changelog: v2.4.0...v2.4.1