October 7, 2026Dashboard 2.42.47

Patch 2 dependency security advisories

Preventive security maintenance. We patched the 2 advisories published on 6 October against dependencies TofuPilot ships, both rated high upstream. We found no way to trigger either flaw through TofuPilot.

  • CVE-2026-96889, a memory flaw in the SVG decoder bundled with our image processing library, which could lead to remote code execution on Linux. TofuPilot never decodes SVG files from untrusted sources.
  • GHSA-6qxp-vccf-f47h, CVSS 7.5, a flaw in the OAuth client of the Model Context Protocol SDK that could send credentials to an authorization server chosen by the remote server. TofuPilot only uses the server side of this SDK.

TofuPilot Cloud requires no action. Self-hosted instances do not need an urgent update either: the fixes come with your next regular image pull. Taking it also stops vulnerability scanners on your side from reporting these versions.

Try these features today