This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 1mo
AI Agents & Assistants
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
agent
ai
astrbot
llm
chatgpt
discord
+9 more
docker
gemini
llama
mcp
openai
python
qq
qqbot
telegram
Affected surfaces
auth
rbac
Summary
AI summaryUpdates Bug Fixes, Highlights, and Release Process across a mixed release.
Full changelog
What's Changed
- 为 OpenAI、Gemini、Anthropic 等模型请求加入可配置的重试机制,并新增请求最大重试次数配置,提升临时网络错误与 5xx 服务端错误下的稳定性。(#8893)
- 新增托管 Core 包下载能力,并加强 Core 与 Dashboard 包下载归档校验。(#8888)
- 支持在请求中加载 workspace skills,并加固 workspace skill 发现流程。(#8884)
- 修复 OpenAPI 文件上传能力,恢复
/api/v1/fileOpenAPI 暴露、文件范围 API Key 与相关文档/客户端产物。 - 修复新版 MCP 中 Streamable HTTP client 重命名导致的兼容问题,并保持
mcp依赖小于 2。 - 加固人格工具边界,确保人格限定的工具范围在主 Agent 请求中正确生效。(#8786)
- 加强 Future Task 所有者校验,避免越权访问定时任务。(#8881)
- 在受限本地文件系统工具中拒绝 hardlink 文件,避免通过工作区 hardlink 别名读写允许目录外的文件。
- 新增
scripts/prepare_release.py,统一 release 分支、版本号、changelog 与校验流程。(#8891) - 明确 OpenAPI Chat 中
username字段的身份含义。(#8880)
What's Changed (EN)
Highlights
- Added configurable retry handling for OpenAI, Gemini, Anthropic, and related provider requests, including a maximum request retry setting to improve stability for transient network failures and 5xx server errors. (#8893)
- Added hosted Core package downloads and strengthened archive validation for hosted Core and Dashboard packages. (#8888)
- Added workspace skills support in requests and hardened workspace skill discovery. (#8884)
Bug Fixes
- Restored OpenAPI file uploads by exposing
/api/v1/file, enabling file-scoped API keys, and regenerating docs/client artifacts. - Fixed compatibility with the renamed MCP Streamable HTTP client while keeping the
mcpdependency below 2. - Hardened persona tool boundaries so persona-restricted tool scopes are enforced correctly in main Agent requests. (#8786)
- Enforced Future Task owner checks to prevent unauthorized scheduled-task access. (#8881)
- Rejected hardlinked files in restricted local filesystem tools to prevent workspace hardlink aliases from reading or overwriting files outside allowed directories.
Release Process
- Added
scripts/prepare_release.pyto standardize release branches, version bumps, changelog generation, and validation. (#8891)
Docs
- Clarified the identity semantics of the
usernamefield in OpenAPI Chat. (#8880)
Security Fixes
- Prevented unauthorized Future Task access by enforcing owner checks
- Rejected hardlink files in restricted local filesystem tools to block out‑of‑bounds reads/writes
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About AstrBot
All releases →Related context
Related tools
Earlier breaking changes
- v4.25.3 Upgrades MiniMax Token Plan default model to M3.
Beta — feedback welcome: [email protected]