🛡️ Security
A maintenance release for the v1 line, carrying the v1 backport of the security fix released in 2.52.0. See the advisory for full details and affected versions.
- GHSA-v36g-jcw9-x7cw (moderate): converting attacker-controlled HTML with deeply nested elements in the local
web_fetchtool could consume excessive CPU and memory. Provider-native web fetching is not affected. Reported by @SounLabs. (#8985)
Patched in 1.107.7; also patched on the v2 line in 2.52.0.
What's Changed
🐛 Bug Fixes
Full Changelog: v1.107.6...v1.107.7