github langgenius/dify 0.15.4
v0.15.4

latest releases: 0.15.6-alpha.1, 1.1.3, 0.15.5...
3 days ago

✨ What’s New in v0.15.4? ✨

Thanks for keeping up with Dify! This patch delivers some important fixes to boost the stability and security of your operations.

Important

This update includes a critical fix for an XSS vulnerability. Cloud users are not affected by this issue.

This version disables the SVG rendering in the message. If you are using our Community Edition and meet all of the following conditions, we recommend that you upgrade to the current version immediately:

  1. Your service is exposed to the internet.
  2. You provide external WebApps.
  3. You have not configured SERVICE_API_URL and FILES_URL on different domains.
  4. You are still using a version lower than 1.0.0

🛠️ Fixes & Improvements

  • Security: Resolved an XSS vulnerability related to rendering SVGs, closing a security gap with help from @iamjoel in #16437.

This update is all about refining the edges and enhancing the user experience—an essential pit-stop on our road to new features and capabilities. Keep those contributions and feedback coming, and let's make Dify even better, together! 🚀

Don't miss a new dify release

NewReleases is sending notifications on new releases.