Beta Preview: Security Patches
/** Beta preview of the critical security fixes shipping in 2026.2.25 stable. */
β Beta release β not recommended for production. Upgrade to 2026.2.25 stable when available.
β¨ Security Patches in this Beta
Enforced origin checks for browser WebSocket clients beyond Control UI/Webchat. Password-auth failure throttling applied to browser-origin loopback attempts.
fileConsent/invoke upload acceptance/decline bound to originating conversation, preventing cross-conversation upload injection via leaked uploadId values.
Rejected hardlinked workspace file aliases in workspaceOnly and applyPatch boundary checks to prevent out-of-workspace read/write via in-workspace hardlink paths.
Enforced DM/group authorization before reaction-only notification enqueue so unauthorized senders cannot inject Signal reaction system events.