Skip to content

Loki Mode

v7.96.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents aider anthropic autonomous ci-cd claude
+13 more
cline code-review devops gemini github-action github-issues loki-mode multi-agent openai-codex openapi pull-request-review sdlc spec-driven-development

Affected surfaces

rbac

Summary

AI summary

Council force-review path now fails CLOSED, preventing unauthenticated approvals when gate functions are missing.

Full changelog

Trust moat: council force-review path fails closed

  • Council force-review path now fails CLOSED (autonomy/run.sh): the
    interval force-review gate chain had the same fail-open hole fixed on the
    default route in v7.95.0 (a missing gate fn silently skipped), letting a
    partial council-library load force-approve completion ungated. It now probes
    the core gate functions first and refuses the force approval if any is missing.
    Found by the wave-4 adversarial bug-hunt.

Breaking Changes

  • Council force-review path now fails CLOSED when any core gate function is missing, reversing previous fail-open behavior.

Security Fixes

  • CVE-2025-XXXXX – Prevented unauthorized council approvals via missing gate functions in the force‑review chain (fail‑open vulnerability fixed).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Loki Mode

Get notified when new releases ship.

Sign up free

About Loki Mode

Multi-agent autonomous SDLC framework. Spec to deployed app. PRD, GitHub issue, OpenAPI/JSON/YAML, or one-line brief. 5 AI providers, 11 quality gates.

All releases →

Related context

Beta — feedback welcome: [email protected]