Development · Articlepublished 8d
Datasette patches a table-permission bypass in 0.65.5 and 1.0a40
Datasette 0.65.5 and 1.0a40 fix a table-permission flaw in which a trailing newline in a requested table name could bypass an authorisation check and expose private rows. Both release lines shipped the fix on 16 September; Datasette remains Apache-2.0 licensed and the disclosure, changelog and patched releases are public.