Skip to content

0.171.5

Choose a tag to compare

@vinhnx vinhnx released this 02 Oct 17:33
· 112 commits to main since this release

Security

Shell approval hardening — GHSA-r249-hpfx-x2w7 / CVE-2026-104247

The destructive-find filter bypass and its follow-up family-key gaps are fixed.
Approval families are now only learned for a bare find/sed/awk program
name; path-qualified (./find, /usr/bin/find), mixed-case, and quote-spliced
($'', $@, {..}, glob) invocations stay exact-only. Wrapper and
environment prefixes (sudo/nice/env, PATH=./bin, env -C <dir>) never
inherit a family approval, and a compound command learns a key only when every
segment is independently read-only and yields its own pattern.

Advisory affected range updated to < 0.171.5; patched in >= 0.171.5.
Fix commit: 5840697c.

What's Changed

0.171.5 - 2026-10-02

Highlights

Bug Fixes

Documentation

  • Order 0.171.5 ahead of 0.171.4 (9cca92e)

Other Changes

Refactors

  • Dedup intent classification and remove dead helpers (e4d48bb)

Full Changelog: 0.171.4...0.171.5