Skip to content

Agent Sessions

v3.4 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agentic-workflow ai ai-coding-agents anthropic claude-code codex
+14 more
codex-cli copilot-cli cursor-agent developer-tools hermes-agent local-first macos openai openclaw opencode session-history session-management transcript-search usage-tracking

Affected surfaces

auth rce_ssrf

Summary

AI summary

Launch/TCC avoids implicit repo probes, performance drops a CPU‑draining animation, and subagents are consistently shown in session listings.

Full changelog

Added

  • Session list: Codex subagent sessions now appear as nested children under their parent in the unified session list. A toggle shows or hides the hierarchy; Cmd+H controls visibility from the keyboard.
  • Agent Cockpit: Active Codex subagent count badge added to HUD rows. Cmd+Shift+S toggles subagent display.

Fixed

  • Agent Cockpit HUD: Codex active subagent badges now use the runtime thread_spawn state DB when available, so open worker agents stay counted even when their rollout files go quiet; passive rollout/lsof heuristics remain as a fallback.
  • Agent Cockpit HUD: Codex runtime subagent counts now resolve the parent session before runtime edge lookup (even when the primary log path is a child rollout), and runtime state DB discovery now honors CODEX_HOME/SessionsRootOverride before falling back to ~/.codex.
  • Codex limits tracking: Visible usage surfaces now prefer auth-backed limits refresh first, fall back to CLI RPC and JSONL only when needed, and keep /status probing as a last resort. Preferences copy now reflects the new source order.
  • Codex limits tracking: /status fallback snapshots now refresh their rate-limit buckets correctly, menu-background surfaces still run the preferred OAuth/CLI refresh chain, and partial live responses no longer leave the other bucket frozen as if the whole snapshot were authoritative.
  • Performance: Eliminated a repeatForever animation CPU drain in session rows that caused sustained energy use even when sessions were idle.
  • Security: SQL queries throughout the indexer are now fully parameterized; regex extraction is hardened against malformed input.
  • Subagents: Subagent sessions are preserved in search results when hierarchy display is disabled, preventing sessions from going missing in filtered views.
  • OpenCode: Parent ID query is guarded for older SQLite schemas that predate the parent_id column.
  • Indexing: Reindex purge now runs after table creation in bootstrap, preventing failures on first-run with no prior DB.
  • Launch/TCC: Session startup now avoids implicit repo filesystem probes while deriving row project names, reducing spurious Photos/Music permission prompts after rebuild/cold launch.
  • Launch restore: Saved Sessions window now registers shared window-open routing callbacks, so menu-bar Open Agent Sessions/cockpit routing still works when only Saved Sessions is restored.
  • Launch/TCC: Preferences agent status rows and OpenCode backend badges now use stored non-probing state under build tooling, avoiding extra PATH, root-directory, and SQLite checks during metadata extraction.

Security Fixes

  • SQL queries in the indexer are fully parameterized; regex extraction hardened against malformed input.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Agent Sessions

Get notified when new releases ship.

Sign up free

About Agent Sessions

Local-first macOS app to browse, search, analyze, and resume supported AI coding-agent session history across Codex, Claude Code, OpenCode, Cursor Agent, Hermes, OpenClaw, Copilot CLI, and more.

All releases →

Related context

Beta — feedback welcome: [email protected]