September 11, 2026Dashboard 2.42.24

Patch 16 dependency security advisories

Preventive security maintenance. We patched the 16 advisories published on 8 September against dependencies TofuPilot ships, two of them rated critical upstream.

  • CVE-2026-75604, CVSS 9.0, unauthenticated remote code execution on Windows filesystems.
  • GHSA-2xp9-vwfh-vxw4, CVSS 9.5, unauthenticated remote code execution through the image optimization path. No CVE assigned.
  • Fourteen further advisories rated high, covering XML parsing, YAML parsing and image decoding.

TofuPilot Cloud requires no action. Self-hosted instances pick these updates up on the next image pull, and updating is recommended.

Try these features today