| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| PrivateBin-2.0.5.zip.asc | 2026-07-11 | 833 Bytes | |
| PrivateBin-2.0.5.tar.gz.asc | 2026-07-11 | 833 Bytes | |
| multiple.intoto.jsonl | 2026-07-11 | 22.9 kB | |
| README.md | 2026-07-11 | 1.1 kB | |
| Release v2.0.5 - Fix rendering unsafe attachments _ base path in JSON API responses source code.tar.gz | 2026-07-11 | 797.0 kB | |
| Release v2.0.5 - Fix rendering unsafe attachments _ base path in JSON API responses source code.zip | 2026-07-11 | 961.4 kB | |
| Totals: 6 Items | 1.8 MB | 2 | |
- CHANGED: Show OS-specific copy hotkey hint (Cmd+c on Mac, Ctrl+c on others) (#1506)
- FIXED: Prevent browsers from rendering unsafe attachments like HTML in a new tab (CVE-2026-55696)
- FIXED: State corruption after "Remove attachment" (#1824)
- FIXED: Copy button is hidden if the document is made as markdown (#1703)
- FIXED: Shortened URLs from YOURLS received but failed to parse (#1844)
- FIXED: Insert only base path in JSON API responses, without GET parameters (CVE-2026-55891)
This release addresses issues with browsers rendering unsafe attachments like HTML and lacking sanitation base path in JSON API responses. More details on this issue can be found in the security advisories: