Skip to content

v2.10.5-lts

Latest

Choose a tag to compare

@liuruibin liuruibin released this 06 Aug 06:41

Security Vulnerability Fixes

  • Security Vulnerability: Fixed missing‑owner‑check at chat‑sharing link endpoint, where chat tokens could be abused to share other users’ conversation content.
  • Security Vulnerability: Fixed privilege escalation allowing regular users to fetch user information of other workspaces via API (#6576).
  • Security Vulnerability: Fixed privilege escalation where any user’s API Key could be used to delete arbitrary files.
  • Security Vulnerability: Fixed the issue that regular users could obtain sensitive information such as other users’ email addresses via API (#6577).

Bug Fixes

  • Knowledge Base: Fixed failure‑to‑load issue for images returned from knowledge bases within conversations.
  • Knowledge Base: Fixed abnormal paragraph content when uploaded PDF contains identical text in titles and body content (#6543).
  • Knowledge Base: Fixed incorrect display of the “Allow preview in knowledge source” option in the web‑knowledge‑base import‑document modal.
  • Agent: Fixed truncated content when copying long conversation text (#6568).
  • Agent: Fixed inaccessible AI‑generated images when agent is embedded in third‑party pages.
  • Agent: Fixed inaccessible images generated by the agent image‑generation node.
  • Agent: Fixed error popup after agent debugging completes, which blocked access to execution details.
  • Agent: Fixed basic agents being able to run retrieval against unpublished knowledge‑base retrieval configurations (#6519).
  • Agent: Fixed image‑loading failure after images are extracted by the file‑content‑extraction node.
  • Agent: Fixed execution failures of agent trigger tasks.
  • Agent: Fixed workflow‑tool‑node outputs not being written into conversation logs.
  • Agent: Fixed failure of the sendMessage method in agent opening remarks to pass user parameters, causing loss of user questions.
  • Agent: Fixed file preview/download failures caused by insufficient permissions in knowledge‑source panel on Q&A page.
  • Agent: Fixed permission‑denied prompts for partial files when downloading multiple uploaded files from conversation logs.
  • Agent: Fixed inaccurate active‑user statistics on overview page caused by residual uncleaned data after conversation‑log cleanup.
  • Role (X‑Pack): Fixed missing permission‑bit controls for certain functions.
  • Shared Resources (X‑Pack): Fixed wrong page redirection when system administrators click “Upload Document” inside shared knowledge bases.
  • Shared Resources (X‑Pack): Fixed access to hit‑test results for shared knowledge bases within workspaces.