Skip to content

chatgpt-on-wechat

v2.1.3 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

โœ“ No known CVEs patched
Read the diff โ†’ Tool health โ†’ What is this tool? โ†’
This release patches 2 known CVEs

Topics

ai ai-agent ai-agents chatgpt-on-wechat claude claude-code
+10 more
codex cowagent deepseek harness llm mcp multi-agent openai openclaw skills

Affected surfaces

auth rce_ssrf

Summary

AI summary

Broad release touches ๐Ÿ›  Improvements & Fixes, ๐Ÿ“š Knowledge Base, ๐Ÿ”’ Security Hardening, and ๐Ÿค– New Models.

Full changelog

๐ŸŒ English | ไธญๆ–‡

๐Ÿ–ฅ Desktop Client

Introducing the CowAgent Desktop client for macOS and Windows โ€” your local super AI assistant, truly ready to use out of the box.

Download: CowAgent Desktop

Highlights:

  • Out of the box: the full Agent runtime is bundled โ€” launch right after install, no need to set up Python or other dependencies
  • Full chat experience: streaming replies, session management, tool-call step display, Markdown rendering, plus sending and previewing images / videos / files
  • Visual management: configuration, models, knowledge base, scheduled tasks, skills, and memory pages mirror the Web console, all manageable in the native UI
  • Channel onboarding: connect messaging channels by scanning a QR code right inside the app
  • Auto update: automatic version checks and one-click updates, with download speed optimized across regions
  • Native experience: first-run onboarding, follows the system language, and platform-adaptive window interactions

๐Ÿ“š Knowledge Base

  • Create & import documents: create new documents or import external ones directly from the UI
  • Automatic index maintenance: the knowledge base index is rebuilt automatically from the actual directory tree, preventing index drift or lost documents
  • Vectorization fix: the index now reuses the unified embedding provider, ensuring real semantic vectors instead of falling back to keyword search

Thanks @yangziyu-hhh

Docs: Knowledge Base

๐Ÿ”Œ On-demand MCP Tool Retrieval

To address context bloat when many MCP tools are connected, we added on-demand tool retrieval: relevant MCP tools are loaded on demand via RAG vector search based on the current task, reducing the context taken up by irrelevant tools.

Thanks @fengyl07

Docs: MCP Tools

๐ŸŒ Traditional Chinese Support

The Web console, logs, and documentation now support Traditional Chinese (zh-Hant); the interface language can follow the system or be switched manually.

Thanks @anomixer (#2935)

๐Ÿค– New Models

  • Added support for claude-sonnet-5 and claude-fable-5
  • Added support for doubao-seed-2-1-pro and doubao-seed-2-1-turbo

Docs: Models

๐Ÿ”’ Security Hardening

  • Sensitive file read protection: hardened access to credential and other sensitive files to prevent bypass reads. Thanks @fengyl07 (#2936)
  • Browser access protection: blocks browser requests targeting internal network and cloud server internal endpoints, reducing the risk of being tricked into reaching internal services. Thanks @Jiangrong-W
  • Safer config parsing: config content is parsed in a safer way to avoid potential code execution risks. Thanks @shunfeng8421

๐Ÿ›  Improvements & Fixes

  • Custom provider support: embedding and vision models can now use custom providers; also fixed a memory query issue on Windows. Thanks @HnBigVolibear
  • More reliable file editing: better preserves original indentation, and fuzzy matching no longer touches unrelated content. Thanks @weijun-xia (#2942)
  • Command output encoding fix: fixed garbled Chinese characters when a command produces large output. Thanks @weijun-xia (#2941)
  • Azure OpenAI fixes: fixed streaming output and related configuration issues for Azure OpenAI. Thanks @Tunnello
  • WeCom Smart Bot: added channel docs for the webhook (callback) mode. Thanks @6vision
  • Deep Dream toggle: added a dedicated deep_dream_enabled switch to enable or disable Deep Dream distillation independently.
  • Stability: improved connection recycling in the Web service and fixed several Self-Evolution issues (#2924 Thanks @santipongth, #2904 Thanks @YLChen-007)

๐Ÿ“ฆ How to Upgrade

  • Desktop client: get the latest version from the download page.
  • Source deployment: run cow update for a one-click upgrade, or pull the latest code and restart. See the upgrade guide.

Release date: 2026.07.08 | Full Changelog

Security Fixes

  • Sensitive file read protection hardened to prevent bypass reads
  • Browser access blocked for internal network and cloud server endpoints

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track chatgpt-on-wechat

Get notified when new releases ship.

Sign up free

About chatgpt-on-wechat

CowAgentๆ˜ฏๅŸบไบŽๅคงๆจกๅž‹็š„่ถ…็บงAIๅŠฉ็†๏ผŒ่ƒฝไธปๅŠจๆ€่€ƒๅ’ŒไปปๅŠก่ง„ๅˆ’ใ€่ฎฟ้—ฎๆ“ไฝœ็ณป็ปŸๅ’Œๅค–้ƒจ่ต„ๆบใ€ๅˆ›้€ ๅ’Œๆ‰ง่กŒSkillsใ€้€š่ฟ‡้•ฟๆœŸ่ฎฐๅฟ†ๅ’Œ็Ÿฅ่ฏ†ๅบ“ไธๆ–ญๆˆ้•ฟ๏ผŒๆฏ”OpenClawๆ›ด่ฝป้‡ๅ’Œไพฟๆทใ€‚ๅŒๆ—ถๆ”ฏๆŒๅพฎไฟกใ€้ฃžไนฆใ€้’‰้’‰ใ€ไผๅพฎใ€QQใ€ๅ…ฌไผ—ๅทใ€็ฝ‘้กต็ญ‰ๆŽฅๅ…ฅ๏ผŒๅฏ้€‰ๆ‹ฉOpenAI/Claude/Gemini/DeepSeek/ Qwen/GLM/Kimi/LinkAI๏ผŒ่ƒฝๅค„็†ๆ–‡ๆœฌใ€่ฏญ้Ÿณใ€ๅ›พ็‰‡ๅ’Œๆ–‡ไปถ๏ผŒๅฏๅฟซ้€ŸๆญๅปบไธชไบบAIๅŠฉ็†ๅ’Œไผไธšๆ•ฐๅญ—ๅ‘˜ๅทฅใ€‚

All releases โ†’

Related context

Beta — feedback welcome: [email protected]