Skip to content
Klyo Changelog

Dependency security refresh and XXE protection on the changelog feed

Bundled dependencies are refreshed to absorb upstream security fixes: Jinja2 3.1.6, python-multipart 0.0.31, undici 7.28.0, DOMPurify 3.4.11, and js-yaml 4.3.0. python-dotenv is bumped to 1.2.2.

The in-product “What’s New” feed parser now uses defusedxml, hardening it against XML external entity (XXE) expansion and similar parser attacks.

SaaS tenants are already patched. Self-hosted customers should upgrade to v1.13.6.