Versie 5.1.3 van SABnzbd is uitgekomen. Met SABnzbd kunnen bestanden van usenet worden gedownload. Dit opensourceprogramma is beschikbaar voor Windows, Linux en macOS, en biedt de mogelijkheid om nzb-bestanden te laden, waarna de juiste bestanden van usenet worden geplukt. Met de ingebouwde webinterface is het mogelijk om het programma via een webbrowser te bedienen. De releasenotes voor deze uitgave kunnen hieronder worden gevonden.
Security fixesSABnzbd 5.1.1, 5.1.2 and 5.1.3 resolve a number of security vulnerabilities. Over the past releases, several security researchers have put a lot of time and effort examining SABnzbd, responsibly reporting their findings, and helping us verify the fixes. We are grateful for their hard work, it has made SABnzbd meaningfully safer for everyone.
For most users the risk is limited: you are only affected if your setup is exposed to untrusted parties. The web interface issues only apply if it can be reached by someone you do not trust. By default, SABnzbd is only accessible from your own device and
External internet accessis set toNo access. If either of those is still at its default, or if you use a proxy service for authentication, you are not affected. The download-processing issues only apply if SABnzbd handles NZBs from a source you do not fully trust, such as a public indexer. If none of that describes your setup, you were never at risk.The safest action is simply to update to 5.1.3. Full details, affected versions, actions and mitigations for each vulnerability are described at: https://sabnzbd.org/5-1-vulnerabilities
Vulnerabilities resolved:
- GHSA-q326-jpxx-jmjc:
__wrapped__dispatch bypass allows unauthenticated API access, fixed in 5.1.3.- GHSA-mjwj-v5mr-cmcg: PAR2 symlink bypass allows pickle remote code execution, fixed in 5.1.3.
- GHSA-rgqj-28c2-gxwp: Critical remote code execution via authentication bypass on configuration endpoints, fixed in 5.1.2.
- GHSA-75g3-96fr-7p2r: High-severity path traversal during post-processing via crafted PAR2/SFV files, fixed in 5.1.2.
- GHSA-xrfq-jhgh-wqch: Critical authentication bypass allowing a valid session without credentials, fixed in 5.1.1.
If you rely on the SABnzbd username and password to keep out untrusted parties, and your setup was exposed, it is recommended that you rotate your SABnzbd username/password and API-key, Usenet server passwords, indexer API-keys used in RSS-feeds, and notification service credentials after updating. See the page above for the full guidance.
Other changes and bug fixes in 5.1.3
- Tighten Compact display mode.
- Directly show usenet server errors instead of parsing them.
- Prevent
database is lockederror when re-evaluating stored RSS jobs.- Added tooltip to explain search filters in Queue and History.
- Windows and macOS: Updated 7zip to 26.03.

:strip_icc():strip_exif()/u/367113/crop63490beb6ee04_cropped.jpg?f=community)
/u/11570/crop64b5645ba45a2.png?f=community)
:strip_icc():strip_exif()/u/73069/zT-Cad.jpg?f=community)
:strip_icc():strip_exif()/u/289675/crop6401bf2c85501_cropped.jpg?f=community)
/u/40697/android%2520eating.png?f=community)
:strip_exif()/u/8422/waarschuwing.gif?f=community)