This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryFixed two security issues: verified initiator token type and ensured the initiator server is trusted.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Fixes verification of initiator token type. Fixes verification of initiator token type. Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Fixes trust verification of initiator server. Fixes trust verification of initiator server. Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Verifies initiator token type correctly. Verifies initiator token type correctly. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Security Fixes
- Verified initiator token type (GHSA‑fix‑5852) closes an authentication bypass
- Ensured initiator server is trusted (GHSA‑fix‑5843) prevents unauthorized access
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]