Download Latest Version 2.11.2 - Client certificate fixes source code.zip (7.6 MB) Google Add to Preferred Sources
Home / 2.11.1
Name Modified Size InfoDownloads / Week
Parent folder
2.11.1 - Security fix for request YAML loading source code.tar.gz 2026-10-05 7.5 MB
2.11.1 - Security fix for request YAML loading source code.zip 2026-10-05 7.6 MB
README.md 2026-10-05 714 Bytes
Totals: 3 Items   15.2 MB 0

Security

Posting 2.11.1 fixes a code-execution vulnerability. Upgrading is recommended for everyone.

Older versions loaded request files (.posting.yaml) with a YAML loader that constructs Python objects. A crafted request file could run arbitrary commands as soon as Posting loaded the collection containing it, for example after cloning a repository or opening a shared collection.

  • Request files are now loaded with YAML's safe loader, and Python object tags are rejected (reported in [#348] and [#383]).
  • Theme files are now loaded with the safe loader too.

Request files that Posting saved itself are unaffected and load as before.

Upgrade: uv tool upgrade posting, or pipx upgrade posting

Source: README.md, updated 2026-10-05