# Self Host Lab

Self-hosting, homelab & media server guides

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Nextcloud Hub 26 Summer Released, Euro-Office Desktop App Coming Soon

DevFeed: [Nextcloud Hub 26 Summer Released, Euro-Office Desktop App Coming Soon](<https://devfeed.tech/articles/nextcloud-hub-26-summer-released-euro-office-desktop-app-coming-soon-31458.md>)

Original publisher: [Read original article](<https://selfhostlab.io/nextcloud-hub-26-summer-release/>)

Author: Christian Rakoot

Published: 2026-09-16T18:32:34Z

Content type: release

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Nextcloud](<https://devfeed.tech/topics/nextcloud.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [microsoft 365](<https://devfeed.tech/topics/microsoft-365.md>)

Tags: [collaboration](<https://devfeed.tech/tags/collaboration.md>), [desktop](<https://devfeed.tech/tags/desktop.md>), [feature](<https://devfeed.tech/tags/feature.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [news](<https://devfeed.tech/tags/news.md>), [office](<https://devfeed.tech/tags/office.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

Nextcloud Hub 26 Summer is live, with the Euro-Office desktop app announced for release in the coming weeks. The update also includes faster browser-based Office features and partner-contributed tools for teams, calendar resource booking, and Tables.

### Source excerpt

Nextcloud's Hub 26 Summer is live today, headlined by a new Euro-Office desktop app arriving in the coming weeks, plus features co-built with partners including IONOS, SURF, and the German state of Schleswig-Holstein.

## n8n Patches 16 Security Vulnerabilities, 12 Rated High Severity

DevFeed: [n8n Patches 16 Security Vulnerabilities, 12 Rated High Severity](<https://devfeed.tech/articles/n8n-patches-16-security-vulnerabilities-12-rated-high-severity-31457.md>)

Original publisher: [Read original article](<https://selfhostlab.io/n8n-16-security-vulnerabilities-patched/>)

Author: Christian Rakoot

Published: 2026-09-16T18:31:20Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [n8n](<https://devfeed.tech/topics/n8n.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [patches](<https://devfeed.tech/topics/patches.md>), [Security](<https://devfeed.tech/topics/security.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [n8n](<https://devfeed.tech/tags/n8n.md>), [news](<https://devfeed.tech/tags/news.md>), [patches](<https://devfeed.tech/tags/patches.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

n8n published a bi-weekly security update disclosing 16 fixed advisories: 12 rated High severity and 4 rated Medium. The article highlights an unauthenticated NoSQL injection in the MongoDB Chat Memory node that can disclose chat history across sessions, along with five High-severity credential-handling advisories.

### Source excerpt

n8n, the self-hosted workflow automation platform covered regularly on this site, published its bi-weekly security update on September 16, 2026. The bulletin, posted on the official n8n Community forum by a member of the n8n security team, discloses 16 advisories fixed since the previous update on September 2: 12 rated High severity and 4 rated [...]

## Uptime Kuma 2.5.4 Patches Critical JSONata Code Execution Flaw

DevFeed: [Uptime Kuma 2.5.4 Patches Critical JSONata Code Execution Flaw](<https://devfeed.tech/articles/uptime-kuma-2-5-4-patches-critical-jsonata-code-execution-flaw-17352.md>)

Original publisher: [Read original article](<https://selfhostlab.io/uptime-kuma-2-5-4-security-release/>)

Author: Christian Rakoot

Published: 2026-09-14T06:55:25Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [monitoring-news](<https://devfeed.tech/tags/monitoring-news.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>), [uptime-kuma-2-5-4](<https://devfeed.tech/tags/uptime-kuma-2-5-4.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Uptime Kuma 2.5.4 fixes a critical JSONata vulnerability that could enable arbitrary code execution on the monitor host, along with a second denial-of-service issue. The release updates jsonata to 2.2.2 and also adds an SFTP monitor type and three notification providers.

### Source excerpt

Uptime Kuma 2.5.4 patches a critical-rated code execution flaw in the JSONata library (CVE-2026-77415, CVSS 9.3) plus a second denial-of-service fix, and adds an SFTP monitor type and three new notification providers. Here's what the flaw actually requires to exploit, and how to update.

## Forgejo 16.0.4 and 15.0.8 Fix Critical Repository Template RCE

DevFeed: [Forgejo 16.0.4 and 15.0.8 Fix Critical Repository Template RCE](<https://devfeed.tech/articles/forgejo-16-0-4-and-15-0-8-fix-critical-repository-template-rce-10719.md>)

Original publisher: [Read original article](<https://selfhostlab.io/forgejo-16-0-4-security-release/>)

Author: Christian Rakoot

Published: 2026-09-12T06:40:18Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Security](<https://devfeed.tech/topics/security.md>), [Template](<https://devfeed.tech/topics/template.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [API](<https://devfeed.tech/topics/api.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [docker-containers](<https://devfeed.tech/tags/docker-containers.md>), [docker-containers-news](<https://devfeed.tech/tags/docker-containers-news.md>), [forgejo](<https://devfeed.tech/tags/forgejo.md>), [git](<https://devfeed.tech/tags/git.md>), [news](<https://devfeed.tech/tags/news.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Forgejo 16.0.4 and 15.0.8 fix a critical remote code execution vulnerability in repository-template creation, along with an API authorization bypass. The article explains how malicious template variables could restore a .git directory with executable hooks and urges affected self-hosted instances to update.

### Source excerpt

Forgejo 16.0.4 and 15.0.8 patch a critical remote code execution vulnerability in repository templates, tracked as CVE-2026-89094 with a CVSS score of 9.9, plus a narrower API permission bypass. Any instance on 16.0.3 or earlier, or 15.0.7 or earlier on the LTS branch, is vulnerable. Here's what happened, why it matters, and how to update.

## Jellyfin 12.0 Is Out: What Breaks Before You Upgrade

DevFeed: [Jellyfin 12.0 Is Out: What Breaks Before You Upgrade](<https://devfeed.tech/articles/jellyfin-12-0-is-out-what-breaks-before-you-upgrade-10723.md>)

Original publisher: [Read original article](<https://selfhostlab.io/jellyfin-12-0-release/>)

Author: Christian Rakoot

Published: 2026-09-08T06:32:10Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Database Migration](<https://devfeed.tech/topics/database-migration.md>), [Database](<https://devfeed.tech/topics/database.md>), [Security](<https://devfeed.tech/topics/security.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [backup](<https://devfeed.tech/tags/backup.md>), [bug](<https://devfeed.tech/tags/bug.md>), [data](<https://devfeed.tech/tags/data.md>), [database](<https://devfeed.tech/tags/database.md>), [jellyfin](<https://devfeed.tech/tags/jellyfin.md>), [jellyfin-12-0-is](<https://devfeed.tech/tags/jellyfin-12-0-is.md>), [jellyfin-news](<https://devfeed.tech/tags/jellyfin-news.md>), [news](<https://devfeed.tech/tags/news.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Jellyfin 12.0 introduces a new versioning scheme and a database rewrite that makes upgrading a consequential operation. Users must meet the supported upgrade path, back up and verify restoration of their configuration and database, complete a full library scan, remove or recompile third-party plugins, and account for removed legacy API and login support.

### Source excerpt

Jellyfin 12.0 shipped on September 7, 2026, after months stuck in release candidate limbo. It's the biggest Jellyfin release since the project forked from Emby in 2018, and the version number itself is the first clue: this build reports as 12.0, not 10.12.0. That's not a typo. Jellyfin has dropped the "10" major prefix that led its version numbers since the fork.

## n8n Patches 18 Security Vulnerabilities in Bi-Weekly Update

DevFeed: [n8n Patches 18 Security Vulnerabilities in Bi-Weekly Update](<https://devfeed.tech/articles/n8n-patches-18-security-vulnerabilities-in-bi-weekly-update-10724.md>)

Original publisher: [Read original article](<https://selfhostlab.io/n8n-september-2026-security-update/>)

Author: Christian Rakoot

Published: 2026-09-06T06:31:02Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [workflow automation](<https://devfeed.tech/topics/workflow-automation.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Code](<https://devfeed.tech/topics/code.md>), [Homelab](<https://devfeed.tech/topics/homelab.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Regular expression](<https://devfeed.tech/topics/regular-expression.md>), [data](<https://devfeed.tech/topics/data.md>), [Git](<https://devfeed.tech/topics/git.md>), [JSON](<https://devfeed.tech/topics/json.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [automation](<https://devfeed.tech/tags/automation.md>), [code](<https://devfeed.tech/tags/code.md>), [data](<https://devfeed.tech/tags/data.md>), [external](<https://devfeed.tech/tags/external.md>), [git](<https://devfeed.tech/tags/git.md>), [json](<https://devfeed.tech/tags/json.md>), [n8n](<https://devfeed.tech/tags/n8n.md>), [n8n-patches-18](<https://devfeed.tech/tags/n8n-patches-18.md>), [news](<https://devfeed.tech/tags/news.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [workflow](<https://devfeed.tech/tags/workflow.md>), [workflow-automation](<https://devfeed.tech/tags/workflow-automation.md>)

### AI overview

n8n's September 2, 2026 bi-weekly security update fixes 18 vulnerabilities: five high-severity and thirteen medium-severity issues. The most serious flaws are two expression-sandbox escapes that can enable arbitrary code execution on self-hosted servers. Other high-severity fixes address denial-of-service, ReDoS, and an OpenAI model-search domain-restriction bypass.

### Source excerpt

Read this article in French: n8n corrige 18 failles de sécurité dans sa mise à jour bi-hebdomadaire n8n is one of the most widely deployed self-hosted workflow automation platforms, often described as the fair-code alternative to Zapier and Make. People use it to move data between apps, trigger scripts on a schedule, and glue together [...]

## Plex Urges Users to Update After Undisclosed Security Fixes in 1.43.3

DevFeed: [Plex Urges Users to Update After Undisclosed Security Fixes in 1.43.3](<https://devfeed.tech/articles/plex-urges-users-to-update-after-undisclosed-security-fixes-in-1-43-3-10727.md>)

Original publisher: [Read original article](<https://selfhostlab.io/plex-security-update-1-43-3/>)

Author: Christian Rakoot

Published: 2026-09-05T06:33:40Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Server](<https://devfeed.tech/topics/server.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [announcement](<https://devfeed.tech/tags/announcement.md>), [docker](<https://devfeed.tech/tags/docker.md>), [media](<https://devfeed.tech/tags/media.md>), [nas](<https://devfeed.tech/tags/nas.md>), [news](<https://devfeed.tech/tags/news.md>), [news-plex](<https://devfeed.tech/tags/news-plex.md>), [pc](<https://devfeed.tech/tags/pc.md>), [plex](<https://devfeed.tech/tags/plex.md>), [plex-urges-users](<https://devfeed.tech/tags/plex-urges-users.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [update](<https://devfeed.tech/tags/update.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Plex released Media Server 1.43.3 and Plex Desktop 1.115.0 to address undisclosed security issues affecting Media Server 1.43.2 and earlier. CVE identifiers and technical details were not public at the time of writing, but Plex urges all server owners and Desktop users to update promptly.

### Source excerpt

Plex has pushed out Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to patch what the company describes only as "a number of security issues." If you run a Plex server on a NAS, a home PC, or in Docker, this is one of those updates worth doing today rather than filing away for later. [...]

## Home Assistant 2026.9 Adds Security Alerts and Removes the VLC Integration

DevFeed: [Home Assistant 2026.9 Adds Security Alerts and Removes the VLC Integration](<https://devfeed.tech/articles/home-assistant-2026-9-adds-security-alerts-and-removes-the-vlc-integration-10722.md>)

Original publisher: [Read original article](<https://selfhostlab.io/home-assistant-2026-9-security-alerts-vlc-removed/>)

Author: Christian Rakoot

Published: 2026-09-03T06:30:38Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Home Assistant](<https://devfeed.tech/topics/home-assistant.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Security](<https://devfeed.tech/topics/security.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>), [VLC](<https://devfeed.tech/topics/vlc-media-player.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [home-assistant-2026-9](<https://devfeed.tech/tags/home-assistant-2026-9.md>), [home-automation](<https://devfeed.tech/tags/home-automation.md>), [home-automation-news](<https://devfeed.tech/tags/home-automation-news.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [news](<https://devfeed.tech/tags/news.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Home Assistant 2026.9 is a stable release that adds conditional security alerts, favorites, shared filtering for History and Activity, accessibility improvements for charts, and a shared-bus Modbus foundation. The release also includes breaking changes, including removal of the VLC integration.

### Source excerpt

Home Assistant 2026.9, "There's room on this bus," is now the stable release. The Security dashboard gains an Active alerts section that only appears when something needs attention, History and Activity share a new Sources panel, and Modbus gets a shared-bus rework. Several breaking changes deserve a read first, starting with the removal of the VLC integration.

## Gitea v1.27.3 Ships 18 Security Hardening Fixes

DevFeed: [Gitea v1.27.3 Ships 18 Security Hardening Fixes](<https://devfeed.tech/articles/gitea-v1-27-3-ships-18-security-hardening-fixes-10720.md>)

Original publisher: [Read original article](<https://selfhostlab.io/gitea-1-27-3-security-hardening/>)

Author: Christian Rakoot

Published: 2026-09-01T06:31:36Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Gitea](<https://devfeed.tech/topics/gitea.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [API](<https://devfeed.tech/topics/api.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [Swift](<https://devfeed.tech/topics/swift.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [code](<https://devfeed.tech/tags/code.md>), [git](<https://devfeed.tech/tags/git.md>), [gitea-v1-27-3-ships](<https://devfeed.tech/tags/gitea-v1-27-3-ships.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [network-security-news](<https://devfeed.tech/tags/network-security-news.md>), [news](<https://devfeed.tech/tags/news.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Gitea v1.27.3 introduces 18 security hardening fixes focused primarily on access control. The release narrows package and API-token access, restricts repository and attachment exposure, strengthens pull-request and artifact trust boundaries, and limits several migration and metadata inputs. It follows earlier Gitea releases that addressed numbered vulnerabilities, but these fixes do not carry dedicated CVE identifiers.

### Source excerpt

Gitea v1.27.3 landed August 29, 2026 with an unusually long SECURITY section: 18 separate access-control hardening fixes, none carrying a CVE identifier. The changes tighten package API scope, attachment paths, repository enumeration, and more. It's the third Gitea security story here in three weeks, following the CVE-2026-59774/60004 patches and CISA's active-exploitation confirmation. Update on your normal schedule.

## Paperless-ngx 3.1.0 Adds AI Workflow Actions and Document Versioning

DevFeed: [Paperless-ngx 3.1.0 Adds AI Workflow Actions and Document Versioning](<https://devfeed.tech/articles/paperless-ngx-3-1-0-adds-ai-workflow-actions-and-document-versioning-10726.md>)

Original publisher: [Read original article](<https://selfhostlab.io/paperless-ngx-3-1-0-ai-workflow-versioning/>)

Author: Christian Rakoot

Published: 2026-08-31T06:39:07Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Compression](<https://devfeed.tech/topics/compression.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bug](<https://devfeed.tech/tags/bug.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [compression](<https://devfeed.tech/tags/compression.md>), [identity](<https://devfeed.tech/tags/identity.md>), [news](<https://devfeed.tech/tags/news.md>), [news-personal-cloud](<https://devfeed.tech/tags/news-personal-cloud.md>), [ocr](<https://devfeed.tech/tags/ocr.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [paperless-ngx](<https://devfeed.tech/tags/paperless-ngx.md>), [personal-cloud](<https://devfeed.tech/tags/personal-cloud.md>), [release](<https://devfeed.tech/tags/release.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [updates](<https://devfeed.tech/tags/updates.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Paperless-ngx 3.1.0 adds automatic AI-based workflow classification, per-document remote OCR selection, OIDC group synchronization, document versioning, configurable ZIP compression, and smaller fixes.

### Source excerpt

Paperless-ngx 3.1.0 landed on August 27, 2026, adding a workflow action that applies AI-generated tag and correspondent suggestions automatically, per-document selective remote OCR, OIDC group sync mapping identity-provider groups to superuser and staff roles, a new versioning system for merging documents into successive versions, configurable ZIP export compression, and numerous smaller UI bug fixes sitewide.

## BookStack Security Update Patches Critical RCE Flaw in v26.05.4

DevFeed: [BookStack Security Update Patches Critical RCE Flaw in v26.05.4](<https://devfeed.tech/articles/bookstack-security-update-patches-critical-rce-flaw-in-v26-05-4-10718.md>)

Original publisher: [Read original article](<https://selfhostlab.io/bookstack-security-update-26-05-4/>)

Author: Christian Rakoot

Published: 2026-08-31T06:36:25Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bookstack-security](<https://devfeed.tech/tags/bookstack-security.md>), [news](<https://devfeed.tech/tags/news.md>), [news-personal-cloud](<https://devfeed.tech/tags/news-personal-cloud.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [personal-cloud](<https://devfeed.tech/tags/personal-cloud.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

BookStack v26.05.4 is a dedicated security release that fixes four vulnerabilities, including a critical authenticated remote code execution flaw involving crafted ZIP imports, an XSS issue, and two draft-page permission bypasses. The article recommends updating and restricting import permissions if an immediate update is not possible.

### Source excerpt

BookStack v26.05.4, released August 24, 2026, is a dedicated security update patching four vulnerabilities: a critical RCE (CVE-2026-82450) exploitable through crafted ZIP imports, an XSS flaw in drawing endpoints, and two permission bypasses affecting draft pages. The BookStack team recommends updating everyone, but especially instances where untrusted users hold general or edit-level access to content.

## Open WebUI v0.11.1 Adds Human-in-the-Loop Tool Approval

DevFeed: [Open WebUI v0.11.1 Adds Human-in-the-Loop Tool Approval](<https://devfeed.tech/articles/open-webui-v0-11-1-adds-human-in-the-loop-tool-approval-10725.md>)

Original publisher: [Read original article](<https://selfhostlab.io/open-webui-v0-11-1-human-in-the-loop/>)

Author: Christian Rakoot

Published: 2026-08-30T06:34:36Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [Homelab](<https://devfeed.tech/topics/homelab.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [homelab](<https://devfeed.tech/tags/homelab.md>), [news](<https://devfeed.tech/tags/news.md>), [news-self-hosted-ai](<https://devfeed.tech/tags/news-self-hosted-ai.md>), [open-webui](<https://devfeed.tech/tags/open-webui.md>), [release](<https://devfeed.tech/tags/release.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [self-hosted-ai](<https://devfeed.tech/tags/self-hosted-ai.md>)

### AI overview

Open WebUI v0.11.1 adds human-in-the-loop approval for selected AI tool calls, allowing users to review actions before execution. The release also fixes terminal-attached chat failures and two calendar timezone-related bugs.

### Source excerpt

Open WebUI v0.11.1 adds human-in-the-loop tool approval, letting you manually confirm certain tool calls before the AI runs them. The release also fixes chats with an attached personal terminal, plus two calendar bugs: new events now default to today's date, and recurring events finally display at the time you actually configured, not a miscalculated one.

## Gitea RCE Flaw Now Under Active Exploitation, CISA Confirms

DevFeed: [Gitea RCE Flaw Now Under Active Exploitation, CISA Confirms](<https://devfeed.tech/articles/gitea-rce-flaw-now-under-active-exploitation-cisa-confirms-10721.md>)

Original publisher: [Read original article](<https://selfhostlab.io/gitea-rce-active-exploitation/>)

Author: Christian Rakoot

Published: 2026-08-29T06:33:49Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Gitea](<https://devfeed.tech/topics/gitea.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Docker Container](<https://devfeed.tech/topics/docker-container.md>)

Tags: [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [docker-container](<https://devfeed.tech/tags/docker-container.md>), [gitea-rce](<https://devfeed.tech/tags/gitea-rce.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [incident](<https://devfeed.tech/tags/incident.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [network-security-news](<https://devfeed.tech/tags/network-security-news.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

CISA confirmed that the critical Gitea vulnerability CVE-2026-60004 is being actively exploited and added it to the Known Exploited Vulnerabilities catalog. The article explains the exploit through Gitea's diffpatch API, which can enable arbitrary code execution, and describes a documented compromise of an outdated self-hosted instance that led to cryptocurrency mining inside a Docker container.

### Source excerpt

CISA has added CVE-2026-60004, the critical Gitea RCE flaw patched in version 1.27.1, to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Help Net Security documented a real compromise: an outdated instance with open registration hit by an automated scanner, ending in a cryptocurrency-mining payload. Here is what changed and how to patch.