AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 79 Bitcoin

Add 2.4.5 changelog

Public commit record

What the developer wrote

Authored by Nicolas Dorier

38/100 · Opaque
Add 2.4.5 changelog
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit only adds a changelog entry for BTCPay Server version 2.4.5. The changelog itself describes several security-related fixes and one breaking change that blocks private-network outbound requests by default to prevent server-side request forgery (SSRF). It also mentions fixes for invoice search scoping, antiforgery validation, payout scoping, refund permissions, and URL validation. Because the commit is just documentation summarizing prior changes, the direct code risk is low, but the listed changes indicate that the 2.4.5 release addresses multiple security issues.

Recommended action

Treat this changelog as a security release note for BTCPay Server 2.4.5. Operators should upgrade to 2.4.5 and review the new ssrfexceptions configuration if they rely on private-network Lightning, LNURL, notification, or webhook targets. Administrators should also audit store-scoped permissions and refund/payout workflows.

Security signals we found

01

SSRF mitigation: private-network outbound requests blocked by default for Lightning, LNURL, invoice notifications, and webhooks

02

Permission escalation fix: employees without approved-pull-payment permission can no longer auto-approve overpayment refunds

03

Cross-store access fix: invoice searches and payout payment actions scoped to current store

04

CSRF protection: antiforgery validation required when changing invoice status in browser

05

URL validation: generated account/password-reset/store-invitation links use configured Base URL and reject non-HTTP(S) values

06

URL validation: Store Website URLs restricted to absolute HTTP/HTTPS in UI and Greenfield API

07

Access-token scoping: failed token revocations kept scoped to authorized store

Risk score

Why this scored 79/100

Our methodology →
Potential impact 25/30
Exploitability 20/25
Stealth signal 10/15
Affected reach 12/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.