This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 4.16.1, and 2026-07-17 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Prevent disk access via require in actions module. Prevent disk access via require in actions module. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Display minimum password length in console complexity message. Display minimum password length in console complexity message. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Keep submit button disabled/loading during password set in login flow. Keep submit button disabled/loading during password set in login flow. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Prevent crash on a stale session cookie during login. Prevent crash on a stale session cookie during login. Source: llm_adapter@2026-07-17 Confidence: high |
— |
Full changelog
4.16.1 (2026-07-17)
Bug Fixes
- actions: prevent disk access via require (afe1086)
- console: display minimum length in password complexity message (#12419) (cc3812a), closes #12390
- login: keep submit button disabled/loading during password set r… (#12429) (0a355f7), closes #12416
- login: prevent crash on a stale session cookie (#12423) (6030a43), closes #11130
Security Fixes
- actions: prevent disk access via require
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]