Skip to content

AstrBot

v4.26.0-beta.9 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

agent ai astrbot llm chatgpt discord
+9 more
docker gemini llama mcp openai python qq qqbot telegram

Affected surfaces

auth rbac

Summary

AI summary

Updates Bug Fixes, Highlights, and Release Process across a mixed release.

Full changelog

What's Changed

  • 为 OpenAI、Gemini、Anthropic 等模型请求加入可配置的重试机制,并新增请求最大重试次数配置,提升临时网络错误与 5xx 服务端错误下的稳定性。(#8893)
  • 新增托管 Core 包下载能力,并加强 Core 与 Dashboard 包下载归档校验。(#8888)
  • 支持在请求中加载 workspace skills,并加固 workspace skill 发现流程。(#8884)
  • 修复 OpenAPI 文件上传能力,恢复 /api/v1/file OpenAPI 暴露、文件范围 API Key 与相关文档/客户端产物。
  • 修复新版 MCP 中 Streamable HTTP client 重命名导致的兼容问题,并保持 mcp 依赖小于 2。
  • 加固人格工具边界,确保人格限定的工具范围在主 Agent 请求中正确生效。(#8786)
  • 加强 Future Task 所有者校验,避免越权访问定时任务。(#8881)
  • 在受限本地文件系统工具中拒绝 hardlink 文件,避免通过工作区 hardlink 别名读写允许目录外的文件。
  • 新增 scripts/prepare_release.py,统一 release 分支、版本号、changelog 与校验流程。(#8891)
  • 明确 OpenAPI Chat 中 username 字段的身份含义。(#8880)

What's Changed (EN)

Highlights

  • Added configurable retry handling for OpenAI, Gemini, Anthropic, and related provider requests, including a maximum request retry setting to improve stability for transient network failures and 5xx server errors. (#8893)
  • Added hosted Core package downloads and strengthened archive validation for hosted Core and Dashboard packages. (#8888)
  • Added workspace skills support in requests and hardened workspace skill discovery. (#8884)

Bug Fixes

  • Restored OpenAPI file uploads by exposing /api/v1/file, enabling file-scoped API keys, and regenerating docs/client artifacts.
  • Fixed compatibility with the renamed MCP Streamable HTTP client while keeping the mcp dependency below 2.
  • Hardened persona tool boundaries so persona-restricted tool scopes are enforced correctly in main Agent requests. (#8786)
  • Enforced Future Task owner checks to prevent unauthorized scheduled-task access. (#8881)
  • Rejected hardlinked files in restricted local filesystem tools to prevent workspace hardlink aliases from reading or overwriting files outside allowed directories.

Release Process

  • Added scripts/prepare_release.py to standardize release branches, version bumps, changelog generation, and validation. (#8891)

Docs

  • Clarified the identity semantics of the username field in OpenAPI Chat. (#8880)

Security Fixes

  • Prevented unauthorized Future Task access by enforcing owner checks
  • Rejected hardlink files in restricted local filesystem tools to block out‑of‑bounds reads/writes

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track AstrBot

Get notified when new releases ship.

Sign up free

About AstrBot

All releases →

Related context

Earlier breaking changes

  • v4.25.3 Upgrades MiniMax Token Plan default model to M3.

Beta — feedback welcome: [email protected]