Dear all,
Two new releases, openfn/lightning:v2.17.0 and openfn/ws-worker:v1.27.2, are out and address several critical security advisories that were detected during an internal “red team” penetration test using the most advanced available AI models. All supported instances of OpenFn have been patched. If you have not already been in touch with Open Function Group, please update your local deployments to address the following advisories:
- Low-privilege users could set privileged project fields, invoke admin-only actions, and download unscrubbed secrets from history exports · Advisory · OpenFn/lightning · GitHub
- Lightning did not verify the PostgreSQL server certificate on SSL database connections · Advisory · OpenFn/lightning · GitHub
- Collections API authorised any project member to modify or destroy collection data regardless of role · Advisory · OpenFn/lightning · GitHub
- Server-side request forgery through OAuth client endpoints, and unprivileged publishing of an instance-wide OAuth client · Advisory · OpenFn/lightning · GitHub
- Channel proxy leaks session cookies and credentials, forges internal requests, and reaches channels across project boundaries · Advisory · OpenFn/lightning · GitHub
- Multiple authentication weaknesses in account-state enforcement, session and socket token revocation, second-factor gating and SSO identity validation · Advisory · OpenFn/lightning · GitHub
- OS command injection in Lightning adaptor metadata fetching (with adaptor-install and dashboard input-validation hardening) · Advisory · OpenFn/lightning · GitHub
- AI assistant authorization: a member of one project could read another project's assistant content and cause it to be sent to an external model · Advisory · OpenFn/lightning · GitHub
- Collaborative editor trusted the client for authorization, allowing cross-project data reads and viewer privilege escalation · Advisory · OpenFn/lightning · GitHub
- Jobs could resolve another project's credential secrets at run time · Advisory · OpenFn/lightning · GitHub
- Cross-project data access: an authorised user could read and modify another project's data by supplying its identifier · Advisory · OpenFn/lightning · GitHub
They are fully backwards compatible with earlier versions. We recommend you upgrade your local instances and run database migrations as soon as possible.
If you have any questions, please don’t hesitate to reach out.
Taylor