Back to Release Notes

v6.13.1

WProofreader core v6.13.1 improves compatibility with editors hosted inside Shadow DOM containers by fixing automatic editor detection, initialization, and auto-search functionality, strengthens the security of the WProofreader Docker image with OpenNLP and Netty vulnerability fixes, and updates the VAPT report.

📝 TL;DR

  • Improved compatibility with editors hosted inside Shadow DOM containers, including automatic editor detection, initialization, and style loading
  • Fixed auto-search functionality in Shadow DOM environments
  • Updated OpenNLP and Netty components in the WProofreader Docker image to address seven reported vulnerabilities
  • Updated the VAPT report to version 6.13.1 and improved vulnerability scanner compliance

🛠 Enhancements

WProofreader JS core (v3.42.6067)

  • Improved Shadow DOM support. Fixed automatic editor detection and proofreader initialization for editable elements hosted inside Shadow DOM containers. WProofreader now correctly detects active editors, preserves instances when editors remain connected to the page, and loads required UI and markup styles within Shadow DOM environments. 

🛡 Security

  • OpenNLP security fixes: Integrated a patched OpenNLP 1.9.4 build with backported fixes for CVE-2026-40682, CVE-2026-42027, and CVE-2026-42440, preserving LanguageTool compatibility while addressing reported vulnerabilities. Scope: OpenNLP components used transitively by LanguageTool and packaged in the WProofreader Docker image. 
  • Netty upgrade: Updated bundled Netty from 4.1.133.Final to 4.1.135.Final to address CVE-2026-44249, CVE-2026-45416, CVE-2026-45674, and CVE-2026-47691. Scope: Netty components used transitively by LanguageTool and packaged in the WProofreader Docker image.
  • VAPT: Update the report v6.13.1