Download Latest Version Release v2.0.6 - Restrict MIME types accepted for PDF _ sanitized SVG previews to prevent HTML render fallback source code.zip (964.9 kB) Google Add to Preferred Sources
Home / 2.0.6
Name Modified Size InfoDownloads / Week
Parent folder
PrivateBin-2.0.6.zip.asc 2026-08-08 833 Bytes
PrivateBin-2.0.6.tar.gz.asc 2026-08-08 833 Bytes
multiple.intoto.jsonl 2026-08-08 22.0 kB
README.md 2026-08-08 1.0 kB
Release v2.0.6 - Restrict MIME types accepted for PDF _ sanitized SVG previews to prevent HTML render fallback source code.tar.gz 2026-08-08 801.5 kB
Release v2.0.6 - Restrict MIME types accepted for PDF _ sanitized SVG previews to prevent HTML render fallback source code.zip 2026-08-08 964.9 kB
Totals: 6 Items   1.8 MB 5
  • CHANGED: Stricter MIME type validation, divergent files get no preview and forced download link
  • CHANGED: Upgrading libraries to: DOMpurify 3.4.12
  • CHANGED: Switch to PHP native JsonException type
  • FIXED: Restrict MIME types accepted for PDF & sanitized SVG previews to prevent HTML render fallback, incl. DOMpurify bypass using multi-byte encoded HTML entities
  • FIXED: Gracefully handle YOURLS replies with a 200 status code but no shorturl, instead of raising a TypeError
  • FIXED: Return "Invalid data." instead of HTTP 500 on malformed v2 JSON payloads (#1883)
  • FIXED: Dead PATH validation guard in Controller, the check for a missing trailing directory separator never ran (#1887)

This release addresses issues with browsers rendering unsafe attachments like HTML. More details on this issue can be found in the security advisory:

Source: README.md, updated 2026-08-08