This release includes 1 security fix for security teams reviewing exposed deployments.
Published 3d
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai
ai-assistant
apple
llm
claude
conversational-ai
+13 more
docker
emotional-ai
google
healthcare-ai
human-in-the-loop
langchain
langgraph
mcp
multi-agent
personal-assistant
self-hosted
skills
vision-ai
Affected surfaces
auth
rce_ssrf
Summary
AI summaryUpdates chat, d3dfb3c8, and 28757f67 across a mixed release.
Full changelog
Changes
- fix(chat): move the aria-controls open/closed branch into useSlashMenu — frontend CC ratchet redded ChatInput at 37>36 (d3dfb3c8)
- fix(chat): axe-valid slash popup wiring + follow-up chips in the user's voice (28757f67)
- fix(web): wrap the share-target page in a Suspense boundary — prod prerender failed on /{lng}/share (c1b511d5)
- fix(security): bump next to 16.2.11 — day-of-release App Router advisories (middleware bypass, Server Actions DoS/SSRF, rewrites SSRF) (5fb0c7f2)
- chore(release): v1.25.16 — UX refinements program: mature conversation surface, custom dashboard, installable PWA, skills gallery + hardened URL install (658b6b7d)
Docker Images
docker pull ghcr.io/jgouviergmail/LIA-Assistant/api:v1.25.16
docker pull ghcr.io/jgouviergmail/LIA-Assistant/web:v1.25.16
Quick Start
git clone https://github.com/jgouviergmail/LIA-Assistant.git
cd LIA-Assistant
cp .env.example .env
docker compose up -d
Full Changelog: https://github.com/jgouviergmail/LIA-Assistant/compare/v1.25.15...v1.25.16
Security Fixes
- Bump next to 16.2.11 — mitigates middleware bypass, Server Actions DoS/SSRF, and rewrites SSRF vulnerabilities (5fb0c7f2)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About LIA
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]