Security Vulnerability Fixes
- Security: Fixed the permission bypass and SSRF security issues in the OSS file service URL acquisition interface. Improved application permission verification, DNS resolution verification, and URL resolution consistency to prevent unauthorized access and intranet request forgery.
Bug Fixes
- Models: Fixed an error when setting the end frame for text-to-video generation using the
wanmodel from Alibaba Cloud Bailian provider (#5111). - Models: Fixed the issue where the image count setting did not take effect in the parameter configuration of Volcano Engine image generation models (#5089).
- Knowledge Base: Fixed the issue where document order became disordered after adjusting document order following document segment migration (#5106).
- Knowledge Base: Fixed abnormal segmentation caused by the intelligent segmentation rule not excluding
#comments inside code blocks. - Agent: Fixed an error in model skill invocation during conversation when the thinking process was enabled in the AI Conversation node and an agent was configured in skills (#4988).
- API Documentation: Fixed the missing
sync_typeparameter in the Web knowledge base synchronization API documentation (#5081).