github yuzutech/kroki v0.32.1

5 hours ago

Security

  • Prevent Vega diagrams from bypassing KROKI_SAFE_MODE=SECURE's URL-loading restriction: the guard only inspected spec.data and the direct children of spec.marks, so a URL-bearing data definition nested inside a group mark (marks[].marks[].data[].url) reached Vega's loader unchecked, allowing SSRF and local file reads (e.g. file:///etc/passwd); separately, an image mark's encode.*.url (e.g. encode.enter.url) is fetched directly by the renderer and wasn't inspected at all, allowing SSRF (e.g. against cloud metadata endpoints) even without any data block. Fixed by recursively scanning every mark, however deeply nested, for a url on either data or encode

Diagram libraries

  • Update bpmn-js to 18.22.1

What's Changed

Full Changelog: v0.32.0...v0.32.1

Don't miss a new kroki release

NewReleases is sending notifications on new releases.