Skip to content

Talon

v3.1.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agentic-ai ai-agent anthropic autonomous-agents llm claude
+6 more
discord-bot mcp model-context-protocol self-hosted telegram-bot typescript

Affected surfaces

auth rbac

Summary

AI summary

Bridge auth now defaults to closed and only the owner can access data at rest.

Full changelog

3.1.1 (2026-07-21)

Bug Fixes

  • security: closed-by-default bridge auth + owner-only at-rest permissions (#596) (60c983d)

Security Fixes

  • Bridge authentication is closed-by-default; at-rest permissions restricted to the owner.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Talon

Get notified when new releases ship.

Sign up free

About Talon

All releases →

Related context

Earlier breaking changes

  • v3.0.0 Removes the talon:// address scheme; use real paths instead.
  • v2.0.0 Removes vfs_list, vfs_read, vfs_write tools and GET /vfs/* routes; eliminates talon ls/cat CLI commands.

Beta — feedback welcome: [email protected]