{"url":"https://api.github.com/repos/plausible/analytics/releases/323141490","assets_url":"https://api.github.com/repos/plausible/analytics/releases/323141490/assets","upload_url":"https://uploads.github.com/repos/plausible/analytics/releases/323141490/assets{?name,label}","html_url":"https://github.com/plausible/analytics/releases/tag/v3.2.1","id":323141490,"author":{"login":"cnkk","id":22169793,"node_id":"MDQ6VXNlcjIyMTY5Nzkz","avatar_url":"https://avatars.githubusercontent.com/u/22169793?v=4","gravatar_id":"","url":"https://api.github.com/users/cnkk","html_url":"https://github.com/cnkk","followers_url":"https://api.github.com/users/cnkk/followers","following_url":"https://api.github.com/users/cnkk/following{/other_user}","gists_url":"https://api.github.com/users/cnkk/gists{/gist_id}","starred_url":"https://api.github.com/users/cnkk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/cnkk/subscriptions","organizations_url":"https://api.github.com/users/cnkk/orgs","repos_url":"https://api.github.com/users/cnkk/repos","events_url":"https://api.github.com/users/cnkk/events{/privacy}","received_events_url":"https://api.github.com/users/cnkk/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOCY_tjc4TQr9y","tag_name":"v3.2.1","target_commitish":"release-v3.2.1","name":"v3.2.1","draft":false,"immutable":false,"prerelease":false,"created_at":"2026-05-15T09:14:39Z","updated_at":"2026-06-01T08:31:08Z","published_at":"2026-05-15T09:15:56Z","assets":[],"tarball_url":"https://api.github.com/repos/plausible/analytics/tarball/v3.2.1","zipball_url":"https://api.github.com/repos/plausible/analytics/zipball/v3.2.1","body":"# Security related update\r\n\r\nThis patch release **fixes a security vulnerability**[`CVE-2026-8467` / `GHSA-55hg-8qxv-qj4p`](https://github.com/phenixdigital/phoenix_storybook/security/advisories/GHSA-55hg-8qxv-qj4p) affecting the following versions of Plausible Community Edition (image: ghcr.io/plausible/community-edition):\r\nTags:\r\n- v3.2\r\n- v3.2.0\r\n- v3\r\n- v3.2.0-rc.0\r\n- v3.1\r\n- v3.1.0\r\n- v3.1.0-rc.1\r\n- v3.1.0-rc.0\r\n- v3.0.1\r\n- v3.0\r\n- v3.0.0\r\n- v3.0.0-rc.6\r\n- v3.0.0-rc.5\r\n- v3.0.0-rc.4\r\n- v3.0.0-rc.3\r\n- v3.0.0-rc.2\r\n- v3.0.0-rc.1\r\n- v3.0.0-rc.0\r\n\r\nThe affected versions expose a `HTTP \"/storybook\"` endpoint which, under certain conditions, allows remote code execution with privileges of system user running the application.\r\n\r\nThis release v3.2.1 of Plausible Community Edition completely removes that endpoint.\r\n\r\n## Who is affected?\r\n\r\nAll deployments of Plausible Community Edition running the following versions:\r\n\r\n- v3.2\r\n- v3.2.0\r\n- v3\r\n- v3.2.0-rc.0\r\n- v3.1\r\n- v3.1.0\r\n- v3.1.0-rc.1\r\n- v3.1.0-rc.0\r\n- v3.0.1\r\n- v3.0\r\n- v3.0.0\r\n- v3.0.0-rc.6\r\n- v3.0.0-rc.5\r\n- v3.0.0-rc.4\r\n- v3.0.0-rc.3\r\n- v3.0.0-rc.2\r\n- v3.0.0-rc.1\r\n- v3.0.0-rc.0\r\n\r\nwhere `HTTP \"/storybook\"` endpoint is exposed to a public or other untrusted network.\r\n\r\n## Mitigation\r\n\r\nAll affected versions of Plausible Community Edition should be updated to v3.2.1 as soon as possible.\r\n\r\nAs an immediate mitigation, it is recommended to block access to HTTP \"/storybook\" endpoint in your reverse proxy configuration or via other applicable means.\r\n\r\n## Changes in this release\r\n\r\n- Remove `HTTP \"/storybook\"` endpoint along with the associated logic\r\n\r\nNo other changes are included in this release.","discussion_url":"https://github.com/plausible/analytics/discussions/6355","reactions":{"url":"https://api.github.com/repos/plausible/analytics/releases/323141490/reactions","total_count":7,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":5,"rocket":0,"eyes":2}}