| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| 2.11.1 - Security fix for request YAML loading source code.tar.gz | 2026-10-05 | 7.5 MB | |
| 2.11.1 - Security fix for request YAML loading source code.zip | 2026-10-05 | 7.6 MB | |
| README.md | 2026-10-05 | 714 Bytes | |
| Totals: 3 Items | 15.2 MB | 0 | |
Security
Posting 2.11.1 fixes a code-execution vulnerability. Upgrading is recommended for everyone.
Older versions loaded request files (.posting.yaml) with a YAML loader that constructs Python objects. A crafted request file could run arbitrary commands as soon as Posting loaded the collection containing it, for example after cloning a repository or opening a shared collection.
- Request files are now loaded with YAML's safe loader, and Python object tags are rejected (reported in [#348] and [#383]).
- Theme files are now loaded with the safe loader too.
Request files that Posting saved itself are unaffected and load as before.
Upgrade: uv tool upgrade posting, or pipx upgrade posting