A critical security fix
We were notified about the critical security bug in Total.js framework. Read a prevention.

A critical security fix for Total.js framework
We were noticed about the critical security bug in Total.js framework, but you are safe if you use a reverse proxy like NGINX or Apache. I'm very grateful for great analyse from security experts Riccardo Krauter, Dario Ragno, Fabio Cogno @ Certimeter Group. So thank you a lot!
The fix below is for all version of Total.js framework between v1.7 and v3.1 version. Just copy security.js file to definitions folder, for example: /your-app-dir/definitions/security.js.
- download fix security.js
- and copy it to
/your-app/definitions/security.js - restart app
Sorry for all troubles.
NEW UPDATE: read comments here https://github.com/totaljs/framework/commit/de16238d13848149f5d1dae51f54e397a525932b
Other posts from Total.js Platform
- 2026-08-21How to write better Total.js Applications using AI?
- 2026-08-01July report 2026
- 2026-07-24Total.js AIModel: a practical foundation for AI-powered workflows
- 2026-07-01June report 2026
- 2026-06-0214 Years of Building the Total.js Platform - Day by Day 🚀
- 2026-06-01May report 2026
- 2026-05-01April report 2026
- 2026-04-28Total.js without NPM? Absolutely. Run the framework from pure Node.js
- 2026-04-01March report 2026
- 2026-03-02February report 2026
