Skip to content
This repository was archived by the owner on Aug 28, 2026. It is now read-only.

v2.84.5

Choose a tag to compare

@adamsachs adamsachs released this 07 May 16:49

Security

  • Fixed DOM-based XSS in fides.js where client-controlled description overrides bypassed the server-side sanitiser when HTML-formatted descriptions were enabled. See GHSA-5qrq-9645-g5g2 / CVE-2026-44541.

Note: 2.84.4 was not released; 2.84.5 is the first public patch on the 2.84.x line containing this fix.

Full Changelog: 2.84.3...2.84.5