This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalVersion v10.4.0 fixes an IDOR vulnerability that enabled hijacking or overwriting another user's integration API.
Why it matters: The release patches a critical (severity 95) IDOR flaw affecting the integration API; operators should upgrade immediately to prevent unauthorized account takeover.
Summary
AI summaryFixed an IDOR vulnerability that allowed users to hijack or overwrite another user's integration.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes IDOR vulnerability allowing hijack/overwrite of another user's integration. Fixes IDOR vulnerability allowing hijack/overwrite of another user's integration. Source: llm_adapter@2026-07-14 Confidence: high |
— |
Full changelog
Updates in this release
- Addressed a IDOR (Insecure Direct Object References) bug wherein a user can hijack/overwrite another user's integration. Thanks to 5ud0 / Tarmo Technologies (@5ud0er) for reporting this.
Security Fixes
- IDOR vulnerability fixed – prevented hijacking/overwriting of another user's integration
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]