Datasette patches two versions against access bugs in mixed public-private instances

single source · 1 articles · safety · confidence: high · first seen 2026-09-11 03:27 UTC

Datasette released security patch versions 1.0a39 and 0.65.4 on 11 September 2026, covering the 1.0 alpha series and the 0.65.x stable line. The fixes matter for publicly exposed instances, especially those mixing public and private tables. Maintainer Simon Willison writes that Sevban Dönmez reported the issues; Willison and Alex Garcia then audited Datasette using Claude Fable 5.1, GPT-5.6, and GPT-6 Astra, spending almost a week on review. They split the work so one person wrote automated tests exposing each bug and the other implemented the fix, so two humans saw each issue.

What this means for you

If you run Datasette on the public web, upgrade now — 0.65.4 for stable, 1.0a39 for the alpha line. The vulnerability affects instances mixing public and private tables; internal-only instances are lower priority but should still patch eventually.

Key facts

  • ·Datasette 1.0a39 and 0.65.4 were released on 11 September 2026. source
  • ·The releases cover the 1.0 alpha series and the 0.65.x stable series. source
  • ·The security fixes are for public web instances, especially those mixing public and private tables. source
  • ·Sevban Dönmez reported the issues that prompted the audit. source
  • ·The audit used Claude Fable 5.1, GPT-5.6, and GPT-6 Astra. source
  • ·Simon Willison and Alex Garcia split work so one wrote automated tests and the other implemented the fix. source

What the sources say

  • Simon Willison (press)Maintainer's post explaining the patches, audit methods, and the split test/fix workflow.

Sources

The original reporting. Follow these — they did the work.

← the wire