Aral Balkan<p>🔒 New Kitten & JSDB Releases</p><p>Security fix, JSDB 6.0.1.</p><p>This is a critical update.</p><p>• JSDB¹ versions 6.0.0 and below suffer from potential data corruption/arbitrary code execution as string keys were not being sanitised in the same way string values were² (so this is relevant to you if you’re storing untrusted data as keys in your data structures in JSDB and/or Kitten databases without carrying out any of your own sanitisation at the application level).</p><p>• The latest Kitten release uses JSDB version 6.0.1. Your deployment servers will automatically update in the next few hours. On your development machines, please run `kitten update` in your terminal or use the Update feature in Kitten Settings from your browser.</p><p>• If you are using Kitten’s Database App Modules³ feature in your apps, you will have installed JSDB manually and you should update your installation to version 6.0.1.</p><p>¹ <a href="https://codeberg.org/small-tech/jsdb/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">codeberg.org/small-tech/jsdb/</span><span class="invisible"></span></a><br>² <a href="https://codeberg.org/small-tech/jsdb/issues/22" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/small-tech/jsdb/i</span><span class="invisible">ssues/22</span></a><br>³ <a href="https://kitten.small-web.org/reference/#database-app-modules" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">kitten.small-web.org/reference</span><span class="invisible">/#database-app-modules</span></a></p><p><a href="https://mastodon.ar.al/tags/Kitten" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Kitten</span></a> <a href="https://mastodon.ar.al/tags/SmallWeb" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SmallWeb</span></a> <a href="https://mastodon.ar.al/tags/JSDB" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JSDB</span></a> <a href="https://mastodon.ar.al/tags/JavaScriptDatabase" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JavaScriptDatabase</span></a> <a href="https://mastodon.ar.al/tags/KittenRelease" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KittenRelease</span></a> <a href="https://mastodon.ar.al/tags/JSDBRelease" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JSDBRelease</span></a> <a href="https://mastodon.ar.al/tags/securityUpdate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securityUpdate</span></a> <a href="https://mastodon.ar.al/tags/criticalUpdate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>criticalUpdate</span></a></p>