Skip to content

v25.12.1-ls240

Latest

Choose a tag to compare

@LinuxServer-CI LinuxServer-CI released this 12 Jan 18:46
c36bdfb

CI Report:

N/A

LinuxServer Changes:

Full Changelog: v25.12.1-ls239...v25.12.1-ls240

Remote Changes:

Security Release

BookStack v25.12.1 has been released.

This is a security release which adds limits to search operations, and adds size checks to ZIP import files before they are extracted.
These changes help prevent potential abuse to host disk space usage and/or service availability.

We recommended to update your instance if untrusted users have ZIP import permissions, or if untrusted users can perform searches.

Thanks to Jeong Woo Lee (@eclipse07077-ljw) and Gabriel Rodrigues (aka TEXUGO) for reporting these vulnerabilities.

Full List of Changes

  • Updated application PHP dependencies.
  • Add some additional resource-based limits. (#5968)
  • Updated translations with latest Crowdin changes. (#5962)