Download Latest Version 4.6.1 source code.tar.gz (19.0 MB)
Email in envelope

Get an email when there's a new version of ROMM

Home / 4.4.1
Name Modified Size InfoDownloads / Week
Parent folder
4.4.1 source code.tar.gz 2025-11-19 23.2 MB
4.4.1 source code.zip 2025-11-19 120.6 MB
README.md 2025-11-19 4.2 kB
Totals: 3 Items   143.8 MB 0

[!CAUTION] This release patches two high (CVE-2025-65027 and CVE-2025-65097) and one moderate (CVE-2025-65096) severity vulnerabilities. An attacker who already has an account (with any role) on the instance can, with a special crafted link, gain full administrative control, create a new admin account, or escalate their own privileges. All previous versions are affected, and all server owners should update to this version as soon as possible.

As a precaution, users may be kicked out of their logged-in session when first accessing the app, editing a game or running a scan, which will regenerate session and CSRF cookies. This should only happen once.

Private or single-user instances are not at risk. Server owners should treat any links to RomM from users as suspicious. Further details will be published in 14 days to give server owners time to upgrade.

Minor changes

Fixes

Other changes

New Contributors

Full Changelog: https://github.com/rommapp/romm/compare/4.4.0...4.4.1

Source: README.md, updated 2025-11-19