ANN: hledger 1.52.3

9 views
Skip to first unread message

Simon Michael

unread,
Aug 27, 2026, 8:06:44 AMAug 27
to hle...@googlegroups.com
hledger 1.52.3 contains more hledger-web security fixes, for an XSS vulnerability when the add form fails, and a bug allowing include directives to be inserted with only `add` permission.  All hledger-web users should upgrade.

A big thanks to Arthur Cinader for helping to find and fix these, in hledger 2.

They're needed in hledger 1 too, so I backported them, as allowed by our latest AI policy. As before, these affect hledger-web; I don't expect to this to arise for hledger or hledger-ui.


Reply all
Reply to author
Forward
0 new messages