mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
python-multipart 0.0.26 closes CVE-2026-40347 (GHSA-mj87-hwqh-73pj), a DoS triggered by large preamble/epilogue data around a multipart boundary. Bambuddy consumes python-multipart transitively through FastAPI/Starlette for form and file-upload parsing, so multipart routes (backup restore, project thumbnail upload, etc.) were exposed. dompurify 3.4.0 picks up the fix for GHSA-39q2-94rc-95cp (function-form ADD_TAGS could bypass FORBID_TAGS). Bambuddy's two call sites use only array-form ALLOWED_TAGS/ALLOWED_ATTR, so the specific bypass was not reachable, but the bump still hardens the sanitizer and clears the audit warning. requirements.txt floor raised to python-multipart>=0.0.26; frontend/package.json caret pinned to ^3.4.0; npm audit and pip audit both report zero outstanding advisories after the bumps.