Upgrade now
Auth
RCE / SSRF
Dependencies
Auth.js + Next.js fixes
↳
v3.29.0
(29d)
—
CVE-2026-49252 + CVE-2026-55698
↳
v3.28.0
(1mo)
—
i18next prototype pollution fixes
↳
v3.24.0
(1mo)
—
CVE-2024-22206 fix
↳
v3.21.0
(1mo)
—
Hono CORS fix
↳
v3.20.0
(1mo)
—
Security fixes
↳
v3.14.0
(1mo)
—
CVE-2024-52011 fix
↳
v3.1.26
(1mo)
—
CVE fixes + SQL injection
Review required
Coerce hostile/garbage input
Review required
Dependencies
Breaking upgrade
Malicious node-ipc detection + CI npm hardening
↳
v3.1.14
(2mo)
—
React CVE-2025-55182
↳
v3.0.22
(3mo)
—
Security fixes
↳
v3.0.21
(3mo)
—
Security fixes
Review required
Auth
RBAC
Privilege escalation + resource gaming fixes
Security fixes
- CVE-2026-XXXXX – Mask token fields in GetTaskDetail response to prevent credential leakage (#226)
Notable features
- New Vulnerability Rules batch expanding AI component detection coverage
- Fingerprint Enhancement with correct new-api matcher syntax (FOFA 100%)
Monitor
Security hardening
↳
v0.74.1
(4mo)
—
Security hardening
↳
v0.71.3
(4mo)
—
OS CVE patches + attestations
Review required
RCE / SSRF
Auth
Email ReDoS fix
Review required
Auth
Dependencies
Credential security hardening
↳
v0.70.4
(4mo)
—
Vuln DB hardening
↳
v0.66.0
(4mo)
—
Security hardening
↳
v0.59.3
(4mo)
—
Audit & security fixes
↳
v0.59.0
(4mo)
—
Security hardening
↳
v0.58.1
(4mo)
—
ClawHub trust hardening
↳
v0.31.3
(5mo)
—
ClawHub trust hardening
Security fixes
- CVE-2025-55182 — detection added for React2Shell vulnerability affecting Dify, NextChat, and LobeChat
↳
v3.4.1
(10mo)
—
CVE-2025-23316 fingerprint
↳
v3.2
(11mo)
—
AIG IP check fix
Security fixes
- Added decoy MCP tools to detect and collect prompt injection attacks
Notable features
- MCP honeypot tools for injection detection
- Real-time attack prompt collection