| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-17 | 1.2 kB | |
| v0.40.4 source code.tar.gz | 2026-09-17 | 62.4 MB | |
| v0.40.4 source code.zip | 2026-09-17 | 63.0 MB | |
| Totals: 3 Items | 125.4 MB | 0 | |
Security patch release for the 0.40 line. Both fixes concern the WASM plugin
installer, which is built by default (wasm-plugins is in the default feature
set) and reachable by any agent with ordinary write access to a Drive — no
admin rights required.
- Reject path traversal in plugin zip asset entries. A zip entry named
assets/../../..was joined onto the plugin directory using the raw, attacker-controlled entry name, allowing arbitrary file write with attacker-controlled content anywhere the server process could write (GHSA-g2q9-fjm7-cmm3). Entry names underassets/must now be plain relative paths of normal components. Reported by @T4ran24. - Reject path traversal in plugin
namespace/nameon uninstall. Both values were read straight off the Plugin resource and joined into filesystem paths, so a../payload could delete arbitrary files or recursively delete a directory (GHSA-vr56-vwrw-w2vg). Both are now validated as a single path segment on every path that reaches the filesystem, with a direct-child check as defense in depth.
Version bumps: atomic_lib 0.40.1 -> 0.40.2, atomic-server 0.40.3 -> 0.40.4 (cli untouched). server's atomic_lib dep pinned to 0.40.2.