Skip to content

LIA

v1.21.14 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai ai-assistant apple llm claude conversational-ai
+13 more
docker emotional-ai google healthcare-ai human-in-the-loop langchain langgraph mcp multi-agent personal-assistant self-hosted skills vision-ai

Affected surfaces

auth rce_ssrf

Summary

AI summary

Added 13 PII fields to INFO‑level log redaction, offloaded seven blocking file I/O operations to threads for non‑blocking performance, and escaped JSON‑LD SEO scripts to prevent breakout.

Full changelog

Latent-debt hardening (CA-1, CA-4, CA-5) — a maintenance release closing three independent residual debts surfaced by the 2026-07 codebase audit. No user-facing feature change, prompt-free, no DB migration; each item was fixed test-first (a failing test before the fix).

🔒 Privacy (CA-1)

13 more field names added to the INFO-level PII log-redaction net — uploaded file names, HITL replies, calendar/task titles, reminder & edited-message bodies, and bulk-operation exclusion text no longer reach INFO logs. Contents stay at DEBUG or redacted; counters and IDs remain at INFO.

⚡ Performance (CA-4)

Seven blocking file reads/writes on hot async paths (generated-image PNG writes, attachment & RAG uploads, document text extraction, skill endpoints, LLM vision image reads) are offloaded via asyncio.to_thread — a multi-MB write no longer freezes concurrent requests (SSE included) during an image generation or a RAG upload.

🛡️ Security (CA-5)

JSON-LD SEO scripts now escape < to its U+003C JSON form through a shared serializeJsonLd helper (every sink + the blog article page), neutralizing </script> breakout from app-compiled dynamic fields (FAQ questions, blog titles/excerpts), with a systemic CI guard against any future raw JSON.stringify in a script.

Tests: red-first for each item; Ruff / Black / MyPy strict clean; full backend and frontend suites green; i18n key parity across all 6 locales. Docs: docs/technical/PII_LOGGING_SECURITY.md and docs/technical/SECURITY.md updated.

Full technical changelog: CHANGELOG.md

Security Fixes

  • JSON-LD SEO scripts now escape to prevent breakout from dynamic fields; CI guard added against raw `JSON.stringify` usage

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track LIA

Get notified when new releases ship.

Sign up free

Beta — feedback welcome: [email protected]