v3.3.7
3.3.7 is a security release. It closes a stored XSS in the pad and timeslider renderer (GHSA-4mx2-rqx5-2pp6).
- Renderer — attribute-pool values can no longer forge class tokens (GHSA-4mx2-rqx5-2pp6, #8302).
linestylefilterappended thestartandlistline-attribute values verbatim to the space-delimited class string thatdomlineparses back, anddomlineemits anytag:token in that string as a raw element. Astartvalue containing a space, which can be planted through a crafted changeset or.etherpadimport, therefore smuggled in a token such astag:img/src=x/onerror=...and rendered a live element with a live event handler for every viewer of the pad and its timeslider. This is the same function as GHSA-f7h5-v9hm-548j but a different token.startis now emitted only when it is an integer andlistonly when it is a plain list type, anddomlineaccepts only a bare element name (letters, digits and hyphens) fortag:tokens, which also covers class strings contributed by plugins. Reported by @arpitjain099.
- Auth — an empty-string password is refused on both login paths (#8261). A
settings.usersentry configured as"password": ""authenticated anyone who submitted an empty password, on the OIDC interaction path and on HTTP Basic. Both already failed closed for a nullish password; an empty string slipped through because it is a string and compares equal to an empty submission. Only explicit misconfiguration produces it, so this is hardening rather than a vulnerability. Reported by Wenhao Wu (Southeast University) while verifying the fix for GHSA-62cj-9j72-mfrh. - Admin — the plugin catalog no longer offers deprecated or known-broken plugins (#8246). The "Available plugins" list was built straight from the plugin feed, so any package the feed knew about could be installed from the admin UI — including packages npm marks deprecated, packages the plugin registry itself could not get working against the current release, and
ep_adminpads2, which is archived upstream and takes over/admin/padswith a template whose scripts core no longer ships, hanging the admin page on "Loading…". Those are now filtered out of the catalog, the admin UI refuses to install one if a stale page asks for it anyway (pnpm run plugins i ep_<name>on the server still overrides), and an already-installed plugin in that state is flagged as deprecated in the Installed plugins list. The npm deprecation lookup is cached for 12 hours and fails open: if the registry cannot be reached the full catalog is still listed. Reported by @JohnMcLear.
v3.3.7
3.3.7 is a security release. It closes a stored XSS in the pad and timeslider renderer (GHSA-4mx2-rqx5-2pp6).
- Renderer — attribute-pool values can no longer forge class tokens (GHSA-4mx2-rqx5-2pp6, #8302).
linestylefilterappended thestartandlistline-attribute values verbatim to the space-delimited class string thatdomlineparses back, anddomlineemits anytag:token in that string as a raw element. Astartvalue containing a space, which can be planted through a crafted changeset or.etherpadimport, therefore smuggled in a token such astag:img/src=x/onerror=...and rendered a live element with a live event handler for every viewer of the pad and its timeslider. This is the same function as GHSA-f7h5-v9hm-548j but a different token.startis now emitted only when it is an integer andlistonly when it is a plain list type, anddomlineaccepts only a bare element name (letters, digits and hyphens) fortag:tokens, which also covers class strings contributed by plugins. Reported by @arpitjain099.
- Auth — an empty-string password is refused on both login paths (#8261). A
settings.usersentry configured as"password": ""authenticated anyone who submitted an empty password, on the OIDC interaction path and on HTTP Basic. Both already failed closed for a nullish password; an empty string slipped through because it is a string and compares equal to an empty submission. Only explicit misconfiguration produces it, so this is hardening rather than a vulnerability. Reported by Wenhao Wu (Southeast University) while verifying the fix for GHSA-62cj-9j72-mfrh. - Admin — the plugin catalog no longer offers deprecated or known-broken plugins (#8246). The "Available plugins" list was built straight from the plugin feed, so any package the feed knew about could be installed from the admin UI — including packages npm marks deprecated, packages the plugin registry itself could not get working against the current release, and
ep_adminpads2, which is archived upstream and takes over/admin/padswith a template whose scripts core no longer ships, hanging the admin page on "Loading…". Those are now filtered out of the catalog, the admin UI refuses to install one if a stale page asks for it anyway (pnpm run plugins i ep_<name>on the server still overrides), and an already-installed plugin in that state is flagged as deprecated in the Installed plugins list. The npm deprecation lookup is cached for 12 hours and fails open: if the registry cannot be reached the full catalog is still listed. Reported by @JohnMcLear.
@formatjs/ts-transformer: 4.5.0
4.5.0 (2026-10-05)
- The following workspace dependencies were updated
- dependencies
- @formatjs/icu-messageformat-parser bumped to 3.5.21
- dependencies
babel-plugin-formatjs: 13.0.7
13.0.7 (2026-10-05)
- The following workspace dependencies were updated
- dependencies
- @formatjs/icu-messageformat-parser bumped to 3.5.21
- @formatjs/ts-transformer bumped to 4.5.0
- dependencies
vue-intl: 8.1.3
8.1.3 (2026-10-05)
- The following workspace dependencies were updated
- dependencies
- @formatjs/icu-messageformat-parser bumped to 3.5.21
- @formatjs/intl bumped to 6.1.3
- dependencies
formatjs_cli: 1.8.0
1.8.0 (2026-10-05)
- deps: update oxc to 0.151 (#7524) (b20b90c)
- deps: update oxc to 0.152 (#7548) (e35b510)
- deps: update ruff to v0.16.9 (#7541) (b91479f)
- macOS Apple Silicon:
formatjs_cli-darwin-arm64 - Linux ARM64:
formatjs_cli-linux-arm64 - Linux x86_64:
formatjs_cli-linux-x64 - Windows x64:
formatjs_cli-win32-x64.exe
# macOS (Apple Silicon)
curl -LO https://github.com/formatjs/formatjs/releases/download/formatjs_cli_v1.8.0/formatjs_cli-darwin-arm64
chmod +x formatjs_cli-darwin-arm64
sudo mv formatjs_cli-darwin-arm64 /usr/local/bin/formatjs
# Linux
curl -LO https://github.com/formatjs/formatjs/releases/download/formatjs_cli_v1.8.0/formatjs_cli-linux-x64
chmod +x formatjs_cli-linux-x64
sudo mv formatjs_cli-linux-x64 /usr/local/bin/formatjs
# Linux ARM64
curl -LO https://github.com/formatjs/formatjs/releases/download/formatjs_cli_v1.8.0/formatjs_cli-linux-arm64
chmod +x formatjs_cli-linux-arm64
sudo mv formatjs_cli-linux-arm64 /usr/local/bin/formatjs
# Windows x64 (PowerShell)
curl.exe -LO https://github.com/formatjs/formatjs/releases/download/formatjs_cli_v1.8.0/formatjs_cli-win32-x64.exe
Verify the checksums:
curl -LO https://github.com/formatjs/formatjs/releases/download/formatjs_cli_v1.8.0/checksums.txt
shasum -a 256 -c checksums.txt
react-intl: 12.1.4
12.1.4 (2026-10-05)
- deps: update dependency @formatjs/icu-messageformat-parser to v3.5.20 (#7515) (23a04a9)
- deps: update formatjs monorepo (major) (#7512) (118166c)
- The following workspace dependencies were updated
- dependencies
- @formatjs/icu-messageformat-parser bumped to 3.5.21
- @formatjs/intl bumped to 6.1.3
- intl-messageformat bumped to 12.1.3
- dependencies
eslint-plugin-formatjs: 8.1.1
8.1.1 (2026-10-05)
- The following workspace dependencies were updated
- dependencies
- @formatjs/icu-messageformat-parser bumped to 3.5.21
- @formatjs/ts-transformer bumped to 4.5.0
- dependencies
@formatjs/unplugin: 1.2.13
1.2.13 (2026-10-05)
- The following workspace dependencies were updated
- dependencies
- @formatjs/icu-messageformat-parser bumped to 3.5.21
- @formatjs/ts-transformer bumped to 4.5.0
- dependencies