| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-05-20 | 2.9 kB | |
| Release v2.0 source code.tar.gz | 2026-05-20 | 146.8 MB | |
| Release v2.0 source code.zip | 2026-05-20 | 153.8 MB | |
| Totals: 3 Items | 300.6 MB | 0 | |
Features
- Added a documentation link tooltip for the Appsmith Base URL setting and implemented trailing-slash normalization. (#41782)
- Added support for the MongoDB Operator in Helm deployments. (#41733)
- Added Ask AI CE stubs and shared file wiring support. (#41692)
Fixes
- Validated request origins before persisting invited users. [APP-15239] (#41826)
- Preserved Redis credentials during
appsmithctl restore. (#41827) - Upgraded
postgresql-jdbcto42.7.11to remediate CVE-2026-42198. (#41812) - Added validation for Git repository URLs. (#41819)
- Prevented unauthenticated access to full OpenAPI documentation. (GHSA-v6jh-fx3m-7xhw) (#41803)
- Fixed a path traversal vulnerability. (GHSA-m4hv-9p7g-56vm) (#41790)
- Upgraded
arangodb-java-driverto7.25.0to remediate CVE-2025-52999. (#41789) - Replaced generic “Response not valid” messages with more actionable error messages for improved observability. (#41769)
- Failed closed for token-bearing emails when
APPSMITH_BASE_URLis unset. (GHSA-j9gf-vw2f-9hrw) (#41767) - Updated Helm charts to use documented image values instead of the undocumented
_imagekey. (#41765) - Fixed a datasource configuration leak in Appsmith App Viewer imports. (GHSA-93mf-9h52-gfxp) (#41764)
- Prevented stored XSS via SQL autocomplete. (GHSA-vjfq-fvfc-3vjw) (#41760)
- Stripped identity fields from imported JSON before persistence. (#41761)
- Prevented HTML entity decoding from corrupting binary file uploads in multipart form data. (#41742)
- Pinned
protobufjsto^7.5.5to address GHSA-xq3m-2v4x-88gg. (#41745) - Upgraded
axiosto1.15.0to address GHSA-3p68-rc4w-qgx5. (#41739) - Upgraded bundled Mongo to 7.x
- Upgraded backend JAVA to 25.x
- Upgraded backed Node to 24.x
- Upgraded bundled MongoDB to 7.x