This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+2 more
Affected surfaces
Summary
AI summaryUpdates Delegation, Documents, and Tasks across a mixed release.
Full changelog
Upgrade note (Docker installs from before 1.2.0): the compose file now
reads operator settings from a.envfile next todocker-compose.yml
(older installs usedconfig.env). If your settings still live in
config.env, rename it —mv config.env .env— or set
OTODOCK_ENV_FILE=config.env. Starting without a.envfile no longer
crash-loops: the proxy detects Docker's silently-created directory and
stops with instructions naming the exact fix.
Added
- The video toolkit. Agents can now produce finished videos end to end.
Three MCPs ship with the platform: video-gen (AI footage, transitions
and Runway Aleph edits, with your Google / Runway / fal.ai keys),
music-gen (ElevenLabs music and sound effects) and tts (voice-overs
via the platform's TTS providers). The video-tools editing MCP
(timelines, transitions, captions, color grading, FFmpeg rendering) is in
the community catalog, installable on any 1.0+ install. - One-command install.
scripts/install.shbootstraps a fresh Docker
install end to end: Docker preflight,.envgeneration, the Ubuntu 24.04+
AppArmor step, and first start. - Chats tell you where they run: a chat stays on the machine it started on,
says so when that differs from the agent's current machine, and an
owner/admin can move it to the current machine with its conversation
reloaded. - Delegation: a session can adopt an existing project as its orchestrator,
and the delegation tool lists each agent's layers and models so requests
are validated instead of failing blind. - The SSH MCP can list its authorized hosts mid-session (
list_ssh_hosts).
Changed
- Interactive terminal sessions are enabled by default, and tool
permission prompts are now risk-based: read-only tools never prompt,
reversible actions stop prompting in Accept Edits mode, and outward-facing
or costly actions always prompt. MCPs without a declared tier keep their
old prompting behavior. - The installer installs into the directory it is run from, refuses your
home directory, and performs fresh installs only, as before. - Per-agent roles decoupled from the platform role: any non-admin user
can hold any per-agent role (manager / editor / viewer). - Shared-only agents bill the person, not the platform: dashboard chats
are attributed to the user whose subscription serves the session, and a
shared chat changing hands recycles the live session under the new sender
so one user's messages never spend another user's account. - Remote agents allowed to run
sshcan read~/.ssh/configand
known_hosts(private keys stay unreadable, writes stay denied).
Fixed
- Interactive terminals: the first message into a cold terminal is no longer
lost, assistant text no longer duplicates, a dying CLI says "process
exited" instead of going blank, opening a terminal no longer overwrites
your clipboard, and Codex permission questions show their card in headless
mode. - Remote machines: replies no longer land one turn late after background
work, the first workspace sync shows live progress instead of silent
minutes, zero-byte files and folder deletions sync correctly, files on the
machine's own disk preview and save reliably, and MCPs that need a newer
Python install it instead of failing forever. - Delegation: results reliably wake sleeping orchestrators (and are replayed
if delivery fails), stopping a worker mid-turn no longer kills its
session, and the "Delegated" badge always completes. - Documents: previews in older chats no longer show "session expired", and
the setup wizard pins document preview to the address you browse from, so
fresh installs get a working preview on any origin. - Tasks: "Run now" shows an honest queued state and attaches the open chat
when streaming starts;run_taskwithwait: trueworks again. - Connected Claude accounts keep their plan tier (Max/Pro) across token
refreshes, so sessions no longer refuse plan-included models. - Voice input no longer appends an invented filler word after you stop
speaking. - Plus a round of smaller fixes across meetings, chat deletion, skill
loading, passkeys, browser-tool contention, and platform shutdown.
Security
- Interactive terminal sessions enforce the chat's permission mode: in
Default mode, file edits, gated shell commands and tool calls prompt in
the terminal before running; mode changes made inside the terminal are
respected. - Display and media hooks are confined to the agent workspace, closing a
path that could read arbitrary proxy-host files into the chat. - OAuth connect pages escape reflected input and confine post-login
redirects; API errors return clean messages and keep exception detail
server-side. - Template and text regexes are linear-time (ReDoS), the per-session Codex
config is written owner-only, and prompt-file loading is confined to the
agent tree. - Dependency refresh across the proxy and bundled MCP servers — every open
Dependabot advisory with an available fix is cleared.
Security Fixes
- Interactive terminal permission enforcement now respects chat mode; display/media hooks confined to agent workspace closing file‑read abuse path.
- OAuth connect pages escape reflected input and confine post‑login redirects preventing open redirection attacks.
- Dependency refresh clears all open Dependabot advisories with available fixes.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About OtoDock
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]