This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Light signalThe v3.14.1 release fixes a vulnerability that allowed spoofing of agent_id on the server and agent.
Why it matters: Patch to v3.14.1 immediately to block agent_id spoofing attacks.
Summary
AI summaryPrevent spoofing of agent_id on the server.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Server prevents agent_id spoofing vulnerability Server prevents agent_id spoofing vulnerability Source: llm_adapter@2026-05-21 Confidence: low |
— |
Full changelog
3.14.1 - 2026-05-12
❤️ Special thanks the security researchers and those who fixed them ❤️
- Thanks to Shivam Kumar (@shivamkumarcyber) and
Ranganatha Rao Sridhar (Praetorian) independently finding and reporting the bug - And @6543 fixing the bugs and orchestrating the communication
🔒 Security
- Server: make sure agent_id can not be spoofed by agent [#6567]
Security Fixes
- Server: agent_id cannot be spoofed by an agent
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About woodpecker
Woodpecker is a simple, yet powerful CI/CD engine with great extensibility.
Related context
Related tools
Beta — feedback welcome: [email protected]