Zammad 6.5.1
ยท Important security updates are included in this release. All self-hosted instances must be updated immediately.
Please read on for details:
ยท Important security updates are included in this release. All self-hosted instances must be updated immediately.
Please read on for details:
A permission issue was identified where agents could see titles of Knowledge Base articles they didnโt have permission to access when using the global search. While the article content remained protected, these entries should not have been visible at all. This has now been corrected.
๐ For more details, please refer to the Security Advisory ZAA-2025-05.
Various sections of the Zammad front end failed to perform the correct HTML escape function when outputting data. This could have allowed HTML injection in the browser. However, execution of JavaScript code was correctly prevented by Content Security Policy.
๐ For more details, please refer to the Security Advisory ZAA-2025-06.
๐ฅ Prefer video over text?
No problem! In his latest YouTube video, Marcel โ aka That Helpdesk Guy โ takes you on a quick, clear, and slightly nerdy tour of the latest security release.
๐ Watch the video
Please note that you must meet the following browser requirements to use this version:
All improvements can be found in the Changelog.
Here you can find information on upgrading your Zammad installation: