Review required
Auth
RBAC
Privilege escalation + resource gaming fixes
Security fixes
- CVE-2026-XXXXX – Mask token fields in GetTaskDetail response to prevent credential leakage (#226)
Notable features
- New Vulnerability Rules batch expanding AI component detection coverage
- Fingerprint Enhancement with correct new-api matcher syntax (FOFA 100%)
Monitor
Security hardening
↳
v0.74.1
(2mo)
—
Security hardening
↳
v0.71.3
(2mo)
—
OS CVE patches + attestations
Review required
RCE / SSRF
Auth
Email ReDoS fix
Review required
Auth
Dependencies
Credential security hardening
↳
v0.70.4
(2mo)
—
Vuln DB hardening
↳
v0.66.0
(2mo)
—
Security hardening
↳
v0.59.3
(2mo)
—
Audit & security fixes
↳
v0.59.0
(2mo)
—
Security hardening
↳
v0.58.1
(2mo)
—
ClawHub trust hardening
↳
v0.31.3
(3mo)
—
ClawHub trust hardening
Security fixes
- CVE-2025-55182 — detection added for React2Shell vulnerability affecting Dify, NextChat, and LobeChat
↳
v3.4.1
(8mo)
—
CVE-2025-23316 fingerprint
↳
v3.2
(9mo)
—
AIG IP check fix
Security fixes
- Added decoy MCP tools to detect and collect prompt injection attacks
Notable features
- MCP honeypot tools for injection detection
- Real-time attack prompt collection