Official security advisories from the Infisical team: CVEs, patched vulnerabilities, and required upgrade actions for self-hosted deployments.
The Infisical team posts here when there’s something security-related you may need to act on. Topics include:
- Security advisories and CVE disclosures affecting Infisical
- Patch releases that fix vulnerabilities, with affected versions and upgrade instructions
- Security-relevant changes to defaults or configuration
- Advisories for vulnerabilities in dependencies that affect Infisical deployments
How this category works:
- Only Infisical staff post here, so subscribing to this category (bell icon > Watching) is a reliable way for self-hosters to get notified of anything requiring action
- Each advisory states affected versions, severity, and what to do
Found a vulnerability? Never post it publicly, here or anywhere else on the forum. Report it through our disclosure policy at Vulnerability Disclosure Policy | Infisical.
For general product news and releases, see Announcements. For non-security bugs, use Issues and Bug Reporting.