ZeroHour
Simon Willisonpublished ()ingested 2
Part of a story covered by 3 sources: “Datasette ships security releases 1.0a39 and 0.65.4 for public/private table bugs” — merged summary and timeline →

Datasette 1.0a39 and 0.65.4 security releases

mediumVulnerabilityimportance 25
AI summary · glm-5.3-flash

Datasette shipped security patches 1.0a39 and 0.65.4 fixing subtle bugs in instances mixing public and private tables, found via an AI-assisted audit.

Datasette released parallel security fixes for its current alpha series (1.0a39) and stable 0.65.x family (0.65.4), advising anyone running a Datasette instance on the public web to update, especially where public and private tables are mixed. The underlying issues were reported by Sevban Dönmez and Alex Garcia, followed by an extensive audit of the codebase using Claude Fable 5.1, GPT-5.6, and GPT-6 Astra. Fixes were developed and reviewed collaboratively over nearly a week. No CVE identifiers or observed exploitation are mentioned in the announcement.

  • Two versions patched: 1.0a39 (alpha) and 0.65.4 (stable 0.65.x line).
  • Public-facing instances mixing public and private tables are the priority for patching.
  • Subtle bugs surfaced by researchers and a frontier-model-assisted security audit.
  • Announcement suggests frontier-model security audits will become standard practice.
  • No CVEs assigned and no in-the-wild exploitation reported.
Full article

Datasette 1.0a39 and 0.65.4 security releases Today we're releasing two new security patch versions of Datasette: 1.0a39 and 0.65.4 - one for the current alpha series and one for the stable 0.65.x family. These are security fixes which you should apply if you are running a Datasette instance on the public web - in particular if that instance mixes both public and private tables. Following issues reported by Sevban Dönmez , Alex Garcia and I ran an extensive audit of Datasette using Claude Fable 5.1, GPT-5.6, and GPT-6 Astra. We then spent almost a week collaborating on and reviewing the fixes. They helped find some very subtle bugs. We'll be incorporating security audits by frontier models…

This source does not provide full text. Read it at simonwillison.net.