Datasette 1.0a40 patches permissions bypass that leaked private rows via trailing newline

JeremyCMorgan · x · 2026-09-26

Datasette 1.0a40 is out with a security fix: a trailing newline in a requested table name could bypass table permissions and expose private rows (GHSA-h547-rmjf-5m2m). Upgrades are urged for anyone serving private data.

The release also adds a background task system for plugins:

Also included: an endpoint for counting matching rows and a batch of bug fixes.

Original post →

More from coding & agent

coding & agent channel →