Skip to content

LIA

v1.14.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai ai-assistant apple llm claude conversational-ai
+13 more
docker emotional-ai google healthcare-ai human-in-the-loop langchain langgraph mcp multi-agent personal-assistant self-hosted skills vision-ai

Affected surfaces

rce_ssrf

Summary

AI summary

Security fix adds CodeQL path injection sanitization using os.path.normpath and startswith.

Full changelog

Changes

  • feat(release): v1.14.0 — Psyche Engine, emotional intelligence & prompt directives overhaul (fdf17c6)
  • docs(getting-started): add detailed Google Cloud, Azure, and Firebase setup procedures (cee354d)
  • fix(security): use os.path.normpath + startswith for CodeQL path injection sanitization (0a26dd3)

Docker Images

docker pull ghcr.io/jgouviergmail/LIA-Assistant/api:v1.14.0
docker pull ghcr.io/jgouviergmail/LIA-Assistant/web:v1.14.0

Quick Start

git clone https://github.com/jgouviergmail/LIA-Assistant.git
cd LIA-Assistant
cp .env.example .env
docker compose up -d

Full Changelog: https://github.com/jgouviergmail/LIA-Assistant/compare/v1.13.10...v1.14.0

Security Fixes

  • fix(security): use os.path.normpath + startswith for CodeQL path injection sanitization (0a26dd3)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track LIA

Get notified when new releases ship.

Sign up free

Beta — feedback welcome: [email protected]