3.8.4.1
*Released Date 18th September 2026*
- Fixed: Security vulnerability that allowed unauthenticated file uploads through the file-upload AJAX endpoint, which could be used to upload disguised executable files.
- Fixed: Command execution risk in the log-file reading fallback.
- Improved: Added hardened validation and directory-level execution protection for the file-upload endpoint.
- Improved: Added parameterized database queries to settings and invitation-code import features, and to several other database queries as a defense-in-depth measure.
- Improved: Replaced several direct filesystem calls with safer alternatives.