Security Vulnerability Fixes
- Security Vulnerability: Fixed missing‑owner‑check at chat‑sharing link endpoint, where chat tokens could be abused to share other users’ conversation content.
- Security Vulnerability: Fixed privilege escalation allowing regular users to fetch user information of other workspaces via API (#6576).
- Security Vulnerability: Fixed privilege escalation where any user’s API Key could be used to delete arbitrary files.
- Security Vulnerability: Fixed the issue that regular users could obtain sensitive information such as other users’ email addresses via API (#6577).
Bug Fixes
- Knowledge Base: Fixed failure‑to‑load issue for images returned from knowledge bases within conversations.
- Knowledge Base: Fixed abnormal paragraph content when uploaded PDF contains identical text in titles and body content (#6543).
- Knowledge Base: Fixed incorrect display of the “Allow preview in knowledge source” option in the web‑knowledge‑base import‑document modal.
- Agent: Fixed truncated content when copying long conversation text (#6568).
- Agent: Fixed inaccessible AI‑generated images when agent is embedded in third‑party pages.
- Agent: Fixed inaccessible images generated by the agent image‑generation node.
- Agent: Fixed error popup after agent debugging completes, which blocked access to execution details.
- Agent: Fixed basic agents being able to run retrieval against unpublished knowledge‑base retrieval configurations (#6519).
- Agent: Fixed image‑loading failure after images are extracted by the file‑content‑extraction node.
- Agent: Fixed execution failures of agent trigger tasks.
- Agent: Fixed workflow‑tool‑node outputs not being written into conversation logs.
- Agent: Fixed failure of the
sendMessagemethod in agent opening remarks to pass user parameters, causing loss of user questions. - Agent: Fixed file preview/download failures caused by insufficient permissions in knowledge‑source panel on Q&A page.
- Agent: Fixed permission‑denied prompts for partial files when downloading multiple uploaded files from conversation logs.
- Agent: Fixed inaccurate active‑user statistics on overview page caused by residual uncleaned data after conversation‑log cleanup.
- Role (X‑Pack): Fixed missing permission‑bit controls for certain functions.
- Shared Resources (X‑Pack): Fixed wrong page redirection when system administrators click “Upload Document” inside shared knowledge bases.
- Shared Resources (X‑Pack): Fixed access to hit‑test results for shared knowledge bases within workspaces.