Skip to content

AstrBot

v4.26.0-beta.8 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent ai astrbot llm chatgpt discord
+9 more
docker gemini llama mcp openai python qq qqbot telegram

Affected surfaces

rce_ssrf deps

Summary

AI summary

Broad release touches 重点更新, 修复, 其他, and Highlights.

Full changelog

What's Changed

重点更新

  • 优化 WebUI 升级流程:Core 更新改为后台任务,并在检测到 WebUI 与 Core 版本错配时提供自动恢复重启引导,避免刷新页面后卡在 Missing API key。(#8846)
  • 增强 QQ 官方机器人群聊能力,支持群消息创建类型,并允许 Webhook 适配器在无缓存 msg_id 时主动发送群消息。(#8838, #8841)

修复

  • 修复人格编辑时重名校验不准确的问题。(#8843)
  • 加固沙箱文件传输与 CUA 健康检查流程,降低异常环境下的文件操作风险。(#8840)

其他

  • faiss-cpu 版本基线从 1.12.0 调整为 1.14.3。(#8837)

What's Changed (EN)

Highlights

  • Improved the WebUI upgrade flow by running Core updates as background tasks and adding guided recovery when WebUI/Core version mismatches are detected, preventing refreshes from leaving users stuck at Missing API key. (#8846)
  • Enhanced QQ Official Bot group chat support with group message create events and proactive Webhook group sends without requiring a cached msg_id. (#8838, #8841)

Bug Fixes

  • Fixed duplicate-name validation when editing personas. (#8843)
  • Hardened sandbox file transfers and CUA health checks to reduce file-operation risk in abnormal environments. (#8840)

Other

  • Changed the faiss-cpu version baseline from 1.12.0 to 1.14.3. (#8837)

Security Fixes

  • Hardened sandbox file transfers and CUA health checks to reduce abnormal‑environment file‑operation risks

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track AstrBot

Get notified when new releases ship.

Sign up free

About AstrBot

All releases →

Related context

Earlier breaking changes

  • v4.25.3 Upgrades MiniMax Token Plan default model to M3.

Beta — feedback welcome: [email protected]