Patch 16 dependency security advisories
Preventive security maintenance. We patched the 16 advisories published on 8 September against dependencies TofuPilot ships, two of them rated critical upstream.
- CVE-2026-75604, CVSS 9.0, unauthenticated remote code execution on Windows filesystems.
- GHSA-2xp9-vwfh-vxw4, CVSS 9.5, unauthenticated remote code execution through the image optimization path. No CVE assigned.
- Fourteen further advisories rated high, covering XML parsing, YAML parsing and image decoding.
TofuPilot Cloud requires no action. Self-hosted instances pick these updates up on the next image pull, and updating is recommended.
