Xml Notepad 2.9.0.21
Fix issue security advisory on DTD processing. Make default Ignore DTD option True, which is more secure.
Fix issue security advisory on DTD processing. Make default Ignore DTD option True, which is more secure.
Fix issue security advisory on DTD processing. Make default Ignore DTD option True, which is more secure.
Fix issue security advisory on DTD processing.
Windows Installer
Windows No Installer (zip)
macOS - Universal
Linux - deb, AppImage or rpm
Windows intel x32 releases are marked -ia32-
ChangeLog:
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2026-03-08)
.hidden similar to many linux desktop file managers. permission to see dotfiles 66f9c95A in any volume is sufficient 6eb4f0anohtml or noscript volflags on the webroot would break the web-UI eb028c9dots volflag still doesn't, but that one is intentionaliv and dj docker images if you do not enable mimallocnohtml and noscript now available as global-options --no-html and --no-script 5f3b76c
-ss paranoia option now also enables --no-html --no-readme --no-logues
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2026-03-08)
this release also fixes GHSA-rcp6-88mm-9vgf but that one is nothing to worry about
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2026-03-08)
GHSA-m6hv-x64c-27mm the nohtml volflag did not prevent javascript inside SVG images from executing -- a malicious user with write-access could upload an SVG file which would execute as javascript when someone opens it 1c9f894
nohtml not being aware that SVG images can execute javascript 1c9f894
nohtml will automatically enable noscript, but noscript can also be useful on its own; see readme/.cpr/ have moved to /.cpr/w/ for easier configuration of allowlists in reverseproxies and authentication middlewares 753ff54
Release 2.24.
Fixes metadata issues.
Fixes duplicate alpha filters issue.
Flatpak fix for Credit Scroll generator.
Bug fixes, G'Mic tool visual glitch fix, media items popover fix.
Fixes logging bug breaking motion tracking create with correctly updated metadata for Flathub.
Fixes logging bug breaking motion tracking create.
Windows Installer
Windows No Installer (zip)
macOS - Universal
Linux - deb, AppImage or rpm
Windows intel x32 releases are marked -ia32-
ChangeLog:
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2026-02-25)
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2026-02-25)
GHSA-62cr-6wp5-q43h could let an attacker execute arbitrary JS by tricking you into clicking a malicious link 31b2801
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2025-09-07)
ac is now half the size it used to be, and iv / dj are each 97 MiB smaller
Windows Installer
Windows No Installer (zip)
macOS - Universal
Linux - deb, AppImage or rpm
Windows intel x32 releases are marked -ia32-
ChangeLog:
Windows Installer
Windows No Installer (zip)
macOS - Universal
Linux - deb, AppImage or rpm
Windows intel x32 releases are marked -ia32-
ChangeLog:
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2025-09-07)
md like before); all other files still require read+write+delete 312f48e d692838descript.ion files no longer require the e2d and e2t options to be enabled 4cb4e82fika option sends the filesystem-indexer on a coffee break
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2025-09-07)
get permission when creating a share 95b827f
X-Forwarded-HTTP-Version 72224d2
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2025-09-07)
connection:close band-aid added in v1.20.4 with a proper fix that doesn't make things slower behind reverseproxiesnth global-option because it was never implemented (thx @stackxp!) 22cdc0fnasm + nix, removed autohotkey + cmake b20d325
Windows Installer
Windows No Installer (zip)
macOS - Universal
Linux - deb, AppImage or rpm
Windows intel x32 releases are marked -ia32-
ChangeLog:
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2025-09-07)
urlform global-option was changed to get
connection:close (don't reuse tcp/uds connections), as giving each client a fresh socket helps avoid all such issues e1eff21 b4fddbc
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2025-09-07)
?smsg=foo 6dcb1ef
smsg configures which HTTP-methods to allow; can be set to GET,POST but default is only POST because GET is dangerous (CSRF)?ls was still a bit jank 0a3a807
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2025-09-07)
vol-nospawn (volflag nospawn) to not automatically create the volume's folder on the server's HDD if it doesn't existvol-or-crash (volflag assert_root) to intentionally crash on startup if a volume's folder doesn't already exist on the server HDD--flo to tweak the log-format used by the -lo option for logging to a file 826e84cunlistc* volflags could not be specified for single-file volumes 2664891ipu option can once again be used to reject connections from certain IP-ranges caf831f
?ls nested virtual folders could return an error 6675039