Oxygen 6.1.2 – Security Update
Oxygen 6.1.2 is now available. This release fixes a security issue in the Design Library import flow.
This issue does not apply to Oxygen Classic. Only Oxygen 6.0 and later are affected.
Security Update
This update fixes an access control issue in three Design Library import endpoints. The endpoints accept a URL, have the server fetch it, and save the response as the site’s imported design data (global CSS variables and selectors), which is rendered on every page. They were reachable without authentication, so a visitor who was not logged in could make the site fetch a URL of their choosing and overwrite that data.
The update requires administrator access for all three endpoints, matching the rest of the Design Library import flow, and validates the URL before the server fetches it.
We discovered this issue during an internal security audit. It was not reported by a third party.
Every site running Oxygen 6.0 or later is affected. Update immediately.
Oxygen Classic not affected.



