Changelog

All notable changes to Vulnotes are documented here.

July 17, 2026

Frontend v0.11.0Backend v0.12.0

Added

  • Air-gapped and standalone editions: run Vulnotes fully offline with no internet access, offline licensing, your own outgoing email server, and password resets that work without email delivery
  • Attack kill chain: build a finding-driven attack narrative in reports, with a per-finding toggle and notes (editor, preview and export)
  • Retest workflow: dedicated retest panel on findings, a findings tab badge, and notification links that jump straight to the exchange
  • Client portal notifications: notification bell with a reliable unread count
  • API key permissions: choose exactly what an API key can access when creating it, including planning
  • Report access control: restrict teams to the reports their members work on, with a report-access toggle in the team dialog
  • Planning privacy: events you can't access show as locked busy blocks instead of full details
  • Vulnerability library: search matches localized titles, and a vulnerability can be opened in a specific language via link
  • Vulnerability templates: simple text field type is back, and duplicate field names are blocked in the builder
  • AI vision settings: choose how image analysis runs (or disable it), with a description-only finding dialog when it's off
  • Report tables: custom cell colors now accept template expressions
  • Clearer template errors: messages point to the page and expression that failed

Security

  • API keys are now strictly limited to their granted permissions everywhere
  • Report titles are safely handled everywhere they render