# 3.4.5 安全修复版本发布

**URL:** https://meta.discourse.org/t/3-4-5-security-fixes-release/369347
**Category:** Announcements
**Tags:** release-notes
**Created:** [2025年六月9日 03:57 UTC](https://meta.discourse.org/t/3-4-5-security-fixes-release/369347 "2025-06-09T03:57:43Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)
#### Post date: [2025年六月9日 03:57 UTC](https://meta.discourse.org/t/3-4-5-security-fixes-release/369347/1 "2025-06-09T03:57:43Z")

</div>

## 安全更新

此版本包含社区和 [HackerOne](https://hackerone.com/discourse) 报告的安全问题修复。

- [Auto-executing third-party code in embedded CodePen iframe · Advisory · discourse/discourse · GitHub](https://github.com/discourse/discourse/security/advisories/GHSA-cm93-6m2m-cjcv)
- [HTML injection when inviting to topic via email · Advisory · discourse/discourse · GitHub](https://github.com/discourse/discourse/security/advisories/GHSA-x8mp-chx3-6x2p)
- [DoS via large URL payload in PM to a bot · Advisory · discourse/discourse · GitHub](https://github.com/discourse/discourse/security/advisories/GHSA-3q5q-qmrm-rvwx)

---

_[View the full topic](https://meta.discourse.org/t/3-4-5-security-fixes-release/369347)._
