Skip to content

l33tdawg/sage

v11.0.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agentic-ai artificial-intelligence bft-consensus bft-network distributed-systems governance

Affected surfaces

rce_ssrf

Summary

AI summary

Updates Quick Start (sage-gui) ```bash, v11, and sage-gui across a mixed release.

Full changelog

SAGE v11.0.1

Sovereign Agent Governed Experience — persistent, governed memory for AI agents.

Quick Start (sage-gui)

# Download and extract for your platform, then:
./sage-gui setup    # Interactive setup wizard
./sage-gui serve    # Start your personal memory node

See the README for full documentation.

Changelog

  • 12c36a52d9288d1519c19e1a81629b39518c222f chore(security): document guarded CodeQL sinks
  • 1cae4ab2d8467c9e8d13502ee84bf1a96529df03 docs(v11): polish launch messaging
  • ba490c6e049f2b64e0e8a5dc53d5414c31fdcb1b fix(security): harden local URL and archive handling
  • a6ddb8fbdffe5564b1a5c1678635c077e9053408 fix(v11): make MRI brain the default launch surface
  • 489db46daec112616d9fd4daf79eb416c3d969df fix(v11): make MRI the only CEREBRUM view
  • a119308940fdbc28225bbb0fa8d2c250ec4d26ee release(v11.0.1): prep patch release

Breaking Changes

  • MRI becomes the only CEREBRUM view, removing any previous alternative views.

Security Fixes

  • Hardened local URL and archive handling — mitigates potential sandbox escape or malicious payload execution (no CVE ID provided).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track l33tdawg/sage

Get notified when new releases ship.

Sign up free

About l33tdawg/sage

Institutional memory for AI agents with real BFT consensus. 4 application validators vote on every memory before it's committed — no more storing garbage. 13 MCP tools, runs locally, works with any MCP-compatible model. Backed by 4 published research papers.

All releases →

Related context

Beta — feedback welcome: [email protected]