Transmission 4.1.3 has been released as a small security-focused bug-fix update to the popular open-source BitTorrent client.
The main fix addresses a potential CSRF issue affecting users with remote access enabled via the web interface or RPC. More specifically, the release fixes a CORS bug that leaked the anti-CSRF nonce.
Transmission 4.1.3 also fixes a use-after-free bug in the peer code, plus a compilation problem when using fmt 12.2 and a test-related build error introduced in Transmission 4.1.2.
For additional details, see the changelog.
Transmission 4.1.3 is now available on the project’s GitHub releases page, along with source archives and platform packages. Users of rolling Linux distros can expect the update to arrive soon via their repositories, while others may need to wait for their distro maintainers to package it.
