New advisory: content/docs/security/offsec-006-slug-ssrf-advisory.mdx Covers CWE-918 SSRF + CWE-20 token exfiltration in promote-tenant-image.sh (molecule-core#933), with vulnerability details, mitigations, and upgrade instructions for self-hosted operators. Also updates security/index.mdx with OFFSEC-006 entry and adds "Full advisory" link in the 2026-05-14 changelog entry. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|---|---|---|
| .gitea/workflows | ||
| app | ||
| audio | ||
| content | ||
| docs/marketing | ||
| lib | ||
| marketing/demos/snapshot-scrub | ||
| .ci-auth-test3-1778443616.txt | ||
| .ci-auth-test4-1778443835.txt | ||
| .gitignore | ||
| mdx-components.tsx | ||
| next.config.mjs | ||
| package-lock.json | ||
| package.json | ||
| postcss.config.mjs | ||
| source.config.ts | ||
| tsconfig.json | ||