Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.
As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.
The fix is included in the latest 2.8.17 & 3.3.5 releases https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17 https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5
You must log in or register to comment.
@FrankM the issue with our package manager should be fixed now, can you try again?