Skip to content

LIA

v1.16.3.1 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

ai ai-assistant apple llm claude conversational-ai
+13 more
docker emotional-ai google healthcare-ai human-in-the-loop langchain langgraph mcp multi-agent personal-assistant self-hosted skills vision-ai

Affected surfaces

deps

Summary

AI summary

Updates Code Fixes, Other Upgrades, and https://claude.com/claude-code across a mixed release.

Full changelog

Security Audit — Full Remediation

Comprehensive security audit resolving all GitHub code scanning alerts and Dependabot vulnerabilities. Zero open issues remain.

Dependency Upgrades (Backend — 12 packages)

| Package | From | To | Reason |
|---------|------|----|--------|
| anthropic | 0.86.0 | 0.89.0 | CVE-2026-34450, CVE-2026-34452 |
| cryptography | 46.0.6 | 46.0.7 | Buffer overflow CVE |
| langchain-core | 1.2.23 | 1.2.28 | f-string validation hardening |
| langchain | 1.2.13 | 1.2.15 | Ecosystem compatibility |
| langgraph | 1.1.3 | 1.1.6 | InjectedToolArg security fix |
| langgraph-prebuilt | 1.0.8 | 1.0.9 | Required by langgraph 1.1.6 |
| fastapi | 0.135.2 | 0.135.3 | Patch |
| uvicorn | 0.42.0 | 0.44.0 | Patch |
| sqlalchemy | 2.0.48 | 2.0.49 | Patch |
| python-multipart | 0.0.22 | 0.0.24 | CVE fixes |
| langfuse | 4.0.2 | 4.0.6 | Patch |
| mypy | 1.19.1 | 1.20.0 | Improved type narrowing |

Dependency Upgrades (Frontend — 14 packages)

| Package | From | To | Reason |
|---------|------|----|--------|
| next | 16.1.7 | 16.2.3 | DoS CVE (Server Components) |
| vite | 7.3.1 | 7.3.2 | 3 HIGH CVEs (file read, path traversal, fs.deny bypass) |
| defu | 6.1.4 | 6.1.5 | Prototype pollution (CVSS 7.5) |
| @tanstack/react-query | 5.90.21 | 5.96.2 | Patch |
| firebase | 12.10.0 | 12.11.0 | Patch |
| tailwindcss | 4.2.1 | 4.2.2 | Patch |
| vitest | 4.1.0 | 4.1.2 | Patch |
| + 7 others | — | — | Minor/patch updates |

Other Upgrades

  • tzdata 2025.3 → 2026.1 (timezone database)
  • types-python-jose dev types update
  • GitHub Actions SHA pins updated (3 actions)

Code Fixes

  • CodeQL #720: Remove redundant hours_elapsed > 0 comparison in PsycheEngine
  • mypy 1.20.0: Remove 5 obsolete # type: ignore[return-value] (improved Literal narrowing)
  • Documentation updated across 11 files to reflect new versions

Security Posture

| Metric | Before | After |
|--------|--------|-------|
| Dependabot vulnerabilities | 8 (3 HIGH) | 0 ✅ |
| Code scanning alerts | 3 | 0 ✅ |
| PRs merged | — | 7 |
| CI status | — | All green ✅ |


🤖 Generated with Claude Code

Security Fixes

  • dep: CVE-2026-34450 in anthropic resolved by upgrading to 0.89.0
  • dep: CVE-2026-34452 in anthropic resolved by upgrading to 0.89.0
  • dep: Buffer overflow CVE fixed in cryptography 46.0.7
  • dep: Multiple HIGH CVSS vulnerabilities (CVE‑xxxx‑xxxx) patched in vite, defu and next

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track LIA

Get notified when new releases ship.

Sign up free

Beta — feedback welcome: [email protected]