ChaosCypher v0.4.2 Patches Streaming Bug, Path Traversal, and Rate-Limit Flaws

ChaosCypher has released v0.4.2, a maintenance update containing 61 bug fixes with no new features or API changes. The most significant fix restores live chat streaming, which had silently failed due to middleware tearing down storage adapters before responses finished sending — the bug was hard to spot because completed answers still appeared on page reload. A second fix closes a path traversal vulnerability where a queued task could create SQLite database files at arbitrary locations via an unsanitised metadata field. Two rate-limiting defects were also corrected: the health endpoint lacked request throttling, and a misconfigured nginx zone caused per-IP login limits to collapse into a single global bucket, posing an availability risk on local networks. Self-hosted users are advised to upgrade, and the previously untested middleware now has seven new test cases covering the fixed behaviour.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in