ZeroHour
Story · 1 source · 3 articlesfirst updated ()2

Datasette ships security releases 1.0a39 and 0.65.4 for public/private table bugs

mediumToolsimportance 25
What's new: Before this release, affected Datasette instances — especially those exposed on the public web with a mix of public and private tables — were vulnerable to the subtle bugs fixed here; the exact technical details are documented in the 'Datasette 1.0a39 and 0.65.4 security releases' blog post rather than the announcements themselves. After the release, operators should update to 1.0a39 (alpha…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Datasette published parallel security releases — 1.0a39 for the 1.0 alpha series and 0.65.4 for the stable 0.x branch — fixing subtle bugs affecting instances that mix public and private tables. The issues were surfaced by researchers and an AI-assisted audit…

Datasette, the open-source data exploration tool, released two coordinated security patches on 2026-09-11: version 1.0a39 in the 1.0 alpha series and version 0.65.4 on the stable 0.65.x/0.x line. Both address subtle bugs, with the priority for patching being instances running on the public web that mix public and private tables. The underlying issues were reported by Sevban Dönmez and Alex Garcia, after which the maintainers conducted an extensive audit of the codebase using the frontier models Claude Fable 5.1, GPT-5.6, and GPT-6 Astra. Fixes were developed and reviewed collaboratively over nearly a week. The announcement includes no CVE identifiers and mentions no observed exploitation, and it suggests that frontier-model-assisted security audits will become standard practice.

  • Two patched versions released: 1.0a39 (1.0 alpha series) and 0.65.4 (stable 0.65.x/0.x branch).
  • Announcements and the joint blog post 'Datasette 1.0a39 and 0.65.4 security releases' published on 2026-09-11.
  • Bugs affect Datasette instances mixing public and private tables; public-facing instances are the top patching priority.
  • Issues reported by Sevban Dönmez and Alex Garcia, followed by a codebase audit using Claude Fable 5.1, GPT-5.6, and GPT-6 Astra.
  • Fixes developed and reviewed collaboratively over nearly a week.
  • No CVE identifiers were assigned.
  • No in-the-wild exploitation was reported.
  • The announcement suggests frontier-model security audits will become standard practice.

Coverage timeline

  1. · 4d ago
    Simon Willison· 24
    datasette 1.0a39

    Datasette 1.0a39 is an alpha security release whose fixes are documented in the Datasette blog post covering it and 0.65.4.

  2. · 4d ago
    Simon Willison· 24
    datasette 0.65.4

    Datasette shipped the 0.65.4 security patch release for its stable branch, with fixes documented in the blog post covering 1.0a39 and 0.65.4.

  3. · 4d ago
    Simon Willison· 25
    Datasette 1.0a39 and 0.65.4 security releases

    Datasette shipped security patches 1.0a39 and 0.65.4 fixing subtle bugs in instances mixing public and private tables, found via an AI-assisted audit.