Version information
Release date: October 14, 2025
Version: V4.3.2.1
RPM version: obshell-4.3.2.1-12025101110
New features
OB-Dashboard is renamed to obshell Dashboard.
Security vulnerability fixes
Fixed the Babel security vulnerability in the indirectly dependent component babel-traverse.
Vulnerability ID: XMIRROR-E5B7141B-7C885C95 | CVE-2023-45133 | CNNVD-202310-954 | CWE-184 CWE-697
Fixed the SheetJS security vulnerability.
Vulnerability ID: XMIRROR-E5B7141B-88045095 | CVE-2023-30533 | CNNVD-202304-1870 | CWE-1321、XMIRROR-E5B714EF-14738C95 | CVE-2024-22363 | CNNVD-202404-675 | CWE-1333
Fixed the Mock.js security vulnerability.
Vulnerability ID: XMIRROR-E5B7141B-88B34695 | CVE-2023-26158 | CNNVD-202312-646 | CWE-1321
Removed the Axios dependency and fixed the cross-site request forgery vulnerability, security vulnerability, and code issue vulnerability in Axios, as well as the Regular Expression Denial of Service (ReDoS) vulnerability.
Vulnerability ID: XMIRROR-E5B7141B-7C5E9795 | CVE-2023-45857 | CNNVD-202311-675 | CWE-352、XMIRROR-E5B714EF-EACCEF95 | CVE-2024-57965 | CNNVD-202501-4033 | CWE-346、XMIRROR-E5B714FA-9AAEB795 | CVE-2025-27152 | CNNVD-202503-921 | CWE-918、XMIRROR-E5B77528-8AC8362B | CWE-1333
Fixed the PublicKeyCallback authorization bypass vulnerability in ServerConfig and the Google Go denial of service vulnerability.
Vulnerability ID: XMIRROR-E5B714EF-14A4FD95, XMIRROR-E5B714FA-AE52B195
Fixed the Google Go security vulnerability, denial of service vulnerability in parsing functions, and Google Go security vulnerability.
Vulnerability ID: CVE-2025-22870, CVE-2024-45338, CVE-2025-22872
Fixed the PGX security vulnerability.
Vulnerability ID: CVE-2024-27289, CVE-2024-27304
Fixed the vulnerability caused by excessive memory allocation due to header parsing in golang-jwt.
Vulnerability ID: CVE-2025-30204
Fixed the vulnerability of unbounded resource allocation in Google Go.
Vulnerability ID: CVE-2025-22868
Fixed the privilege escalation vulnerability in Azure Identity Libraries and Microsoft Authentication Library.
Vulnerability ID: CVE-2024-35255
Fixed the vulnerability of information leakage in the logs of HashiCorp go-retryablehttp.
Vulnerability ID: CVE-2024-6104
