Changelog #27

Changelog #27

Changelog #27

Changelog #27

June 12: This Week's Improvements and Bug Fixes

June 12: This Week's Improvements and Bug Fixes

June 12: This Week's Improvements and Bug Fixes

Jun 12, 2025

Jun 12, 2025

Improvements & Bug Fixes

Security

  • Invitation Email Hardening: Resolved a security vulnerability in organization invitation emails, reported by Taha Khan, that could have allowed for potential phishing attacks. Organization names that resemble domains are no longer automatically converted into clickable links by email clients.

  • Magic Link Authentication Flow: Strengthened the magic link authentication flow to address a vulnerability reported by Taha Khan. This fix hardens the system against user enumeration attacks and prevents the issuance of duplicate magic links.

Share