Release 4.3.2

15.07.2026

RELEASE NOTES:

New Features:

  • Prompt Templates Module: New dedicated module for managing AI prompt templates, featuring an embedded md-editor-v3 editor
  • MintMCP Login View: Added a dedicated authentication view for connecting to the MintMCP server
  • MintMCP Internal Authorization: Added internal authorization handling for agent access to MCP tools
  • MintMCP Tooling Expansion: Extended MintMCP with documentation retrieval, report invocation, many-to-many relationship handling, MCP Apps support, and built-in CRM tools with an agent–tool interaction loop
  • MintMCP Automated Regression Tests: Added an automated regression test suite covering MCP tools
  • OpenID Connect (OIDC) & SSO Support: Added OIDC authentication and improved SSO login to allow simultaneous use of classic login/password alongside SSO
  • SAML Support in New API: Added SAML authentication support to the modern API layer
  • Events — Candidate Support: Events can now be linked to candidate records
  • Recurrence Until a Given Date: Added the ability to set recurring records to repeat until a specific date
  • Progress Bar During Recurrence Save: Added a progress indicator while saving recurring records
  • File Attachments on Candidates & Candidatures: Added file attachment support on Candidate and Candidature records
  • Image Preview on Record View: Images attached to a record are now previewed directly on the record view
  • Recently Viewed — Real-Time Update: The “Recently viewed” list now updates immediately when a record view is opened
  • Scroll to Invalid Field on Validation: The form now automatically scrolls to the first field that fails validation
  • Close Tasks from Dashlet: Tasks can now be closed directly from the dashlet
  • List View — Select All Records: Added a “select all” option on list views
  • Offboarding for More Employee Statuses: Offboarding generation now supports Active, During Termination, and Terminated employee statuses
  • Missing API V8 Endpoints: Added previously missing endpoints to the legacy V8 API
  • Notification Screen Redirect: Clicking a notification now redirects to the relevant record or screen
  • Instance Operation Modes: Added configurable operation modes for a MintHCM instance
  • WCAG Keyboard Accessibility: Improved keyboard navigation and focus handling across the homepage, list views, forms, and general navigation
  • Subpanel Modifications: Various subpanel configuration improvements

Security Fixes:

  • Content-Security-Policy (CSP): Introduced a CSP header to reduce XSS and injection attack surface
  • Third-Party JS Library Updates: Updated jQuery, YUI, FullCalendar, and jsTree to patch known vulnerabilities
  • Field Hiding in API V8: Prevented sensitive fields from being exposed via the legacy V8 API
  • Markdown File Access Restriction: Restricted public access to markdown documentation files
  • Self-XSS via login_language Parameter: Fixed improper input handling allowing self-XSS through the login_language parameter
  • IDOR via Subpanel Endpoint: Added missing parent-record ACL check on the subpanel endpoint that allowed cross-record data access
  • Stored XSS in Comments Module: Sanitized the description field before rendering via v-html
  • Authenticated SQL Injection in Legacy V8 API: Fixed SQL injection in filter handling of in/not_in operators
  • Restricted Public Directories and Files: Blocked access to directories and files that should not be publicly reachable
  • Removal of ESList: Removed the legacy ESList module, which contained multiple security issues and is now superseded by the Vue frontend

Bug Fixes:

  • Fixed the installer by replacing the faulty component
  • Fixed view logic that was not executing correctly
  • Fixed non-clickable links inside subpanels
  • Fixed the forgot-password flow
  • Fixed an ElasticSearch error triggered by missing records
  • Fixed an issue preventing record saves
  • Fixed field requirement mismatch on the Birthdate field in Candidates
  • Fixed duplicate notification entries in the bell icon
  • Fixed incorrect language display for list view column headers
  • Fixed several issues identified in Studio, including field editing and entity generator randomly clearing unrelated entities
  • Fixed record creation failure in the Terms of Employment module
  • Fixed missing confirmation notification on save
  • Fixed multiple errors in the Delegations/Costs module
  • Fixed multiple errors in the Work Schedules/Work Time module
  • Fixed a relation issue with the Office field preventing record creation in the Room module
  • Fixed a server error (Error 500) preventing record creation in the Knowledge module
  • Fixed record creation from an Employee subpanel for Training records
  • Fixed several minor bugs in Contracts and Terms of Employment
  • Fixed a conflict between browser autofill and floating labels on the login form
  • Fixed an authentication error in the API
  • Fixed an issue preventing meetings from being closed via the dashlet
  • Fixed issues in the recurrence view
  • Fixed filter behavior on the search view
  • Fixed logo link behavior for Cmd/Ctrl-click (open in new tab)
  • Fixed incorrect search results for meeting participants
  • Fixed menu module ordering not persisting in view options
  • Fixed a crash when sorting the Employees list
  • Fixed a permission issue blocking non-admin users from accessing MintMCP tools
  • Fixed incorrect status display on the Ratings dashlet
  • Fixed missing scrollbars causing a critical UX issue
  • Fixed the sidebar collapse button’s background color
  • Fixed text splitting behavior when pressing Enter
  • Fixed the Certificates subpanel behavior on Employee records
  • Fixed field handling exceptions when duplicating a meeting
  • Fixed several issues from Greens testing, including problems with relate fields
  • Fixed several bugs reported from production use of MintMCP
  • Fixed responsive layout issues in the sidebar menu at various resolutions
  • Fixed incorrect date handling for MCP-created meetings
  • Improved the warning message shown when adding a new Terms of Employment condition
  • Fixed relation propagation when creating a Candidature from a Candidate record

More info about release: https://github.com/minthcm/minthcm/releases/tag/4.3.2

STAY UP TO DATE: