Security Patch: This release fixes multiple security vulnerabilities, including account takeover via OIDC email linking, guest session hijacking, local file read / SSRF through document conversions, and a DNS-rebinding bypass of the previous URL import SSRF fix (CVE-2026-54054). All users should update promptly, especially instances exposed to untrusted users or with ALLOW_UNAUTHENTICATED=true. Thank you to @tonghuaroot, @GEONWOOHAN, @Tike00, @archnexus707, and @Ankith-B for responsibly reporting these issues!
Beyond security, v2.1.0 brings a big batch of new features and fixes:
- Chunked file uploads and downloads, so large files work behind reverse proxies with request size limits (thanks @veno501)
- Paste files directly into Transmute from your clipboard (thanks @veno501)
- Apple iWork support: convert Pages and Numbers documents (#249)
- Custom CSS support for PDF conversions (thanks @RyoSXu)
- MP3 to M4B audiobook conversion (thanks @AlyanPremani05)
- Animation is now preserved in animated-to-animated conversions, including animated WebP (thanks @A-S-Manoj)
- Added Slovenian (thanks @veno501) and Greek (thanks @pixelschaos) translations
- Settings page and dropdown UI refresh (thanks @ManelTech and @Trithereon)
Security Fixes
- GHSA-gp9p-77f3-j7g5: OIDC login could link to an existing account (including admins) based on an unverified email claim. Linking now requires
email_verifiedfrom the provider. - GHSA-38pw-jjq6-6w6p: Guest sessions could be resumed from a known guest UUID. The guest cookie is now HMAC-signed.
- GHSA-8mfq-273g-2cr7: DNS rebinding could bypass URL import SSRF protections. Connections are now pinned to the validated address.
- GHSA-q3fc-r99p-5gj7 / GHSA-jcqc-6m64-4xv6: Document conversions could read local files or fetch arbitrary URLs. Pandoc now runs with
--sandboxand WeasyPrint only resolves inlinedata:URIs. - GHSA-6h5p-x9v3-h6x5: Changing a password no longer works without the current password.
- GHSA-xv67-5v66-38qv: Disabled accounts can no longer use existing JWTs.
Upgrade Notes
- Changing your password now requires your current password (
current_passwordonPATCH /api/users/me). - Existing guest sessions will not resume after upgrading; guests will start a fresh session.
- OIDC users whose provider does not send
email_verified: truewill no longer be automatically linked to an existing local account by email. - Documents that reference remote or local external resources (images, includes) will no longer pull those in during conversion; unresolvable markdown images fall back to their alt text.
Changes
- security: bulk vuln fixes (#296) (7b8b565)
- feat: add Greek (el) translation (#291) (8e77f14 & f369bb7)
- feat(frontend): improve dropdown UI and style (#289) (55fcd29)
- feat(settings): group appearance and conversion in one card with a centered save button (#265) (3d06fac)
- feat: add iWork converter and LibreOffice support for Pages and Numbers (fixes #249) (f09cf8d)
- feat: slovenian localization (#257) (cac2ca0)
- feat: add chunked file uploads and downloads for reverse-proxy compatibility (#241) (#248) (9cc077d)
- feat: file pasting support (#243) (closes #235) (c4552c1)
- feat: add custom CSS support for PDF conversion (#214) (7fdae1f)
- feat: add MP3 to M4B conversion support (#210) (#211) (0bfca37)
- fix(ffmpeg): increase timeout values (closes #284) (#286) (19aecbb)
- fix(settings): use theme primary colour for toggles and save button (#277) (e35ced0)
- fix(auth): style login error as an error box in red for both local and OIDC view (#275) (e94827c)
- fix(i18n): update language detection to prevent caching and ensure live navigator locale (fixes #246) (08dffc0)
- fix(i18n): remove nonExplicitSupportedLngs option from i18next initialization (fixes #237) (03c768c)
- fix: add support for staging animated WebP as APNG for FFmpeg conversion (fixes second part of #213) (e746a7c)
- fix: restore animation in animated-to-animated format conversions (#216) (4fc40d9)
- fix: allow Scout results upload to continue on error (a9ff811)
- fix(tests): add matchMedia mock for jsdom compatibility (510172f)
- fix: correct indentation for sha256 computation status message (55ffeb7)
- refactor: add type hints to ConverterRegistry methods (#293) (30e49d0)
- chore(docker): update Calibre and Drawio versions in Dockerfile (closes #285, closes #287, closes #290) (cfb63c8)
- chore(docker): update Calibre, Pandoc, and Drawio versions in Dockerfile (closes #279, closes #273, closes #270, closes #269, closes #267) (08adbfd)
- chore(deps): update Pandoc and Drawio versions in Dockerfile (fixes #260, fixes #266) (17c9f05)
- chore(docker): update Calibre and Drawio versions in Dockerfile (fixes #251) (3443240)
- chore(deps): update Dockerfile release pins for Calibre, Pandoc, and Draw.io (closes #240, closes #239, closes #233) (97659b2)
- chore: bump DRAWIO_VERSION from 30.3.6 to 30.3.14 (#224) (92b6aa5)
- chore: bump DRAWIO_VERSION from 30.2.6 to 30.3.6 (closes #218) (#219) (6db7b98)
- chore: update Calibre version and checksums to 9.11.0 (fixes #217) (f5078c6)
- chore(deps): bump weasyprint from 68.1 to 70.0 (#281) (66c4fbe)
- chore(deps): bump yt-dlp from 2026.6.9 to 2026.7.4 (#238) (cf24983)
- chore(deps): bump pillow from 12.2.0 to 12.3.0 (#228) (24de48e)
- chore(deps): bump pillow-heif from 1.2.1 to 1.3.0 (#227) (fa7c115)
- chore(deps): bump react-router and react-router-dom in /frontend (#258) (aa028d8)
- chore(deps): bump undici from 7.28.0 to 7.29.0 in /frontend (#250) (339bdde)
- chore(deps): bump @vitest/mocker and vitest in /frontend (#280) (a434f29)
- chore(deps-dev): bump js-yaml from 4.2.0 to 4.3.2 in /frontend (#247, #282) (5dfb596 & 6700584)
- chore(deps-dev): bump browserslist from 4.28.1 to 4.28.9 in /frontend (#278) (11daba4)
- chore(deps-dev): bump @humanfs/node from 0.16.7 to 0.16.8 in /frontend (#272) (b679875)
- chore(deps-dev): bump postcss-selector-parser in /frontend (#271) (17c4ff1)
- chore(deps-dev): bump postcss from 8.5.15 to 8.5.25 in /frontend (#242) (75d881f)
- chore(deps-dev): bump brace-expansion from 5.0.6 to 5.0.7 in /frontend (#230) (3f2db5f)
- chore: update screenshots (d1cb894)
- docs: update YouTube demo link in README (4be1075)
- docs: update README to clarify file conversion and compression capabilities (4de05bd)
Version Information
- Full version:
v2.1.0 - Minor version tag:
v2.1 - Major version tag:
v2
Updated Tags
v2.1→v2.1.0(created)v2→v2.1.0(updated)