This is a security release, upgrading is recommended.
- Fixed an XSS issue when rendering iframes in markdown.
- Iframes only accept
http(s)links, and SVG sources are no longer allowed. - Iframe rendering is disabled in message markdown.
This is a security release, upgrading is recommended.
http(s) links, and SVG sources are no longer allowed.