About the Security Updates category

Official security advisories from the Infisical team: CVEs, patched vulnerabilities, and required upgrade actions for self-hosted deployments.

The Infisical team posts here when there’s something security-related you may need to act on. Topics include:

  • Security advisories and CVE disclosures affecting Infisical
  • Patch releases that fix vulnerabilities, with affected versions and upgrade instructions
  • Security-relevant changes to defaults or configuration
  • Advisories for vulnerabilities in dependencies that affect Infisical deployments

How this category works:

  • Only Infisical staff post here, so subscribing to this category (bell icon > Watching) is a reliable way for self-hosters to get notified of anything requiring action
  • Each advisory states affected versions, severity, and what to do

Found a vulnerability? Never post it publicly, here or anywhere else on the forum. Report it through our disclosure policy at Vulnerability Disclosure Policy | Infisical.

For general product news and releases, see Announcements. For non-security bugs, use Issues and Bug Reporting.