Greenshot 1.3.323 Released — Security Fixes and Reliability Improvements
While working on Greenshot 1.4 to provide additional features and more stability, we didn’t want to have you waiting for things you can already have now. So with 1.3.319 we want to stabilize Greenshot to make it more reliable for our users. We selectively picked improvements we already made in 1.4 and made them work for 1.3. You can download Greenshot from the official download page.
Most of the improvements were provided by the community and we are extremely grateful for their support! Besides that we appreciate every single help and interaction, some members of the community are even more outstanding, so a special thanks for @Christian-Schulz, @danrhodes and @FF-Brown they even combined their invested time to work, also with other contributors, on features and bugs together.
If you like Greenshot, please make sure you give us a star on https://github.com/greenshot/greenshot When companies want to support open source, one of their key criteria to select projects is the amount of stars on GitHub.
🔒 Security Fixes
We strongly recommend that all Greenshot 1.3 users update to version 1.3.323. This release fixes several security issues:
- TLS certificate validation was disabled process-wide, potentially exposing OAuth tokens and uploads to connected services—including Imgur, Box, Dropbox, Flickr, Confluence, and Jira—to man-in-the-middle attacks. Thanks to @sondt99, @lihnucs, and @dungNHVhust for reporting this issue. See the GHSA-q4w7-9m8v-53fm security advisory for details.
- Manipulated
CF_DIBV5clipboard data could cause an out-of-bounds read and denial of service. We thank @hacker1984 for reporting this issue. See the GHSA-4674-75g5-79mx security advisory for details. - Opening a manipulated SVG file could cause a server-side request forgery. We thank @Zenquiem for reporting this issue. See the GHSA-mmr7-mfv6-wp78 security advisory for details.
- @jklingen updated dependencies to address known vulnerabilities, including Inno Setup 6.2.2 for CVE-2025-15595 and log4net 3.3.0 for CVE-2026-40021.
🛠️ Reliability Improvements
Many of the fixes below were first developed for Greenshot 1.4 and have now been deliberately backported to 1.3, with credit retained for the contributors who made the original changes:
- @danrhodes fixed an editor crash on open (issue #925, PR #1003); improved saving to locked or inaccessible files (issue #946, PR #986); fixed a crash when changing the icon size in settings (issue #1007, PR #1010); corrected CTRL behavior while scaling (issue #1055, PR #1087); fixed an error when creating a capture (issue #1021, PR #1022); kept line thickness within its valid range (issue #1142, PR #1151); fixed a race condition in editor layout updates (issue #1169, PR #1210); and fixed several region-capture crashes (issues #1153, #1019, and #1031, PR #1154).
- Robin Krom (@Lakritzator) fixed the tray icon disappearing permanently in RemoteApp/RAIL sessions (issue #1324, PR #1348) and improved handling of the OneDrive hotkey setting (issue #1170).
- Christian Schulz (@Christian-Schulz) fixed instability caused by disposing of a shared font when changing the icon size (PR #981) and resolved inconsistencies when saving file formats (PR #1024).
- @overlord fixed several toast notification problems, including a cross-thread exception (PR #1147).
🖼️ Configurable Border Effect
@weihongji added a setting in Greenshot.ini to configure the Border effect, giving you more control over the editor effect (PR #730). This was their first contribution to Greenshot—welcome, and thank you!
🧹 Cleaner Installations and Smoother Upgrades
Robin Krom (@Lakritzator) improved the installer cleanup so it removes additional leftover files from older Greenshot versions (PR #1092).
Christian Schulz (@Christian-Schulz) made Greenshot 1.3 close automatically when the Greenshot 1.4 installer upgrades it through the Windows Restart Manager (PR #1109), preventing conflicts during the upgrade.
Full Changelog
For a complete list of changes in the 1.3 series, see the Greenshot 1.3 changelog.
