An important security update is released. It fixes two serious vulnerabilities discovered and reported to us by security researcher pearl:
* text messages in chat were incorrectly handled which allowed attackers to execute arbitrary code on victim's wallet. ...
* restore from full backup function allowed file paths with directory traversal (../) characters in backup archive, which could enable an attacker to overwrite important user files ...
Since the two vulnerabilities are now publicly disclosed and each can be used to inflict serious damage to Obyte users who are not aware of them yet, the hub at obyte.org will refuse connections from non-upgraded wallets to keep them safe. All known operators of other hubs have been notified and recommended to apply the same policy.
Only GUI wallets are affected by the vulnerabilities and the upgrade is mandatory for them, headless nodes (wallets, hubs, relays) are not affected.
Please upgrade https://github.com/byteball/obyte-gui-wallet/releases