| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| PrivateBin-2.0.6.zip.asc | 2026-08-08 | 833 Bytes | |
| PrivateBin-2.0.6.tar.gz.asc | 2026-08-08 | 833 Bytes | |
| multiple.intoto.jsonl | 2026-08-08 | 22.0 kB | |
| README.md | 2026-08-08 | 1.0 kB | |
| Release v2.0.6 - Restrict MIME types accepted for PDF _ sanitized SVG previews to prevent HTML render fallback source code.tar.gz | 2026-08-08 | 801.5 kB | |
| Release v2.0.6 - Restrict MIME types accepted for PDF _ sanitized SVG previews to prevent HTML render fallback source code.zip | 2026-08-08 | 964.9 kB | |
| Totals: 6 Items | 1.8 MB | 5 | |
- CHANGED: Stricter MIME type validation, divergent files get no preview and forced download link
- CHANGED: Upgrading libraries to: DOMpurify 3.4.12
- CHANGED: Switch to PHP native JsonException type
- FIXED: Restrict MIME types accepted for PDF & sanitized SVG previews to prevent HTML render fallback, incl. DOMpurify bypass using multi-byte encoded HTML entities
- FIXED: Gracefully handle YOURLS replies with a 200 status code but no shorturl, instead of raising a TypeError
- FIXED: Return "Invalid data." instead of HTTP 500 on malformed v2 JSON payloads (#1883)
- FIXED: Dead PATH validation guard in Controller, the check for a missing trailing directory separator never ran (#1887)
This release addresses issues with browsers rendering unsafe attachments like HTML. More details on this issue can be found in the security advisory: