Download Latest Version v3.33.0-rc10 source code.zip (19.4 MB) Google Add to Preferred Sources
Home / v3.32.5
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-09-25 2.6 kB
v3.32.5 source code.tar.gz 2026-09-25 14.4 MB
v3.32.5 source code.zip 2026-09-25 17.5 MB
Totals: 3 Items   31.9 MB 0

v3.32.5

A security roll-up: hardens request-driven regexes against ReDoS, closes a path-traversal hole in the default payload storage, and clears outstanding CVE/CodeQL alerts in the UI.

What's Changed

  • fix(core): prevent path traversal in DummyPayloadStorage (#1651) — the default payload storage (used whenever no external S3/GCS storage is configured, so reachable in dev and default deployments) resolved caller-supplied paths against payloadDir with no validation in both upload() and download(), letting a ../-style path read or write outside the payload directory. Paths now route through a validateAndResolvePath() that normalizes, rejects residual .., and verifies the canonical path stays within payloadDir — mirroring the earlier MockExternalPayloadStorage fix (#723). Thanks @Denimworld12.
  • fix(security): replace the backtracking ${...} regex in ParametersUtils with a linear scanner (#1654) — the pattern that finds ${...} expressions is applied to every string task parameter, including output returned by workers, and its match time grew polynomially with nesting depth (a ~3 KB string of ${${...}} nested 1000 deep took over 30 seconds). Expressions are now located in a single brace-depth pass with identical semantics — $${ escaping, nested expressions, and an unclosed expression swallowing the rest of the string all behave as before. Thanks @Naman-Gururani. (Fixes [#1638])
  • fix(security): hoist Pattern and prevent ReDoS in the index query builders (#1648) — PostgresIndexQueryBuilder and SqliteIndexQueryBuilder compiled their parsing regex per call and used a pattern that could catastrophically backtrack on long all-letter search input. The pattern is now compiled once and hardened so malformed queries fail fast instead of hanging the search path. Thanks @jhaabhijeet864. (Fixes [#1640])
  • fix(ui): resolve ws to CVE-2024-37890 patched versions (#1672) — pins the transitive ws dev-dependency up via yarn resolutions (jsdom/ws → 7.5.13, webpack-dev-server/ws → 8.21.3), clearing the CVE alert. Thanks @nthmost. (Fixes [#643])
  • fix(security): remove no-op identity replacement in the errorInspector path helper (#1660) — drops a .replace(/\]\[/g, "][") that replaced ][ with itself (a CodeQL js/identity-replacement alert); adjacent brackets like [0][1] are valid lodash nested-access syntax and were always passed through unchanged. Thanks @nthmost. (Fixes [#1642])

Full Changelog: https://github.com/conductor-oss/conductor/compare/v3.32.4...v3.32.5

Source: README.md, updated 2026-09-25