- Fixed a critical host-shell escape in
deer-flowby hardeningLocalSandboxProvider. - Closed unauthenticated bot proxy access in
OpenViking. - Fixed task API ownership leakage in
OpenViking. - Mitigated stored XSS in
deer-flowby enforcing safe downloads for active artifact content. - Blocked unsafe
.ovpackZIP member paths duringOpenVikingimport. - Fixed stale commit-state recovery on current
mainin theOpenVikingopencode plugin.
| Issue Class | Repo | Merged PR |
|---|---|---|
| Critical shell escape | bytedance/deer-flow | #1547 |
| Stored XSS hardening | bytedance/deer-flow | #1389 |
| Task ownership leakage | volcengine/OpenViking | #1182 |
| Unauthenticated bot proxy access | volcengine/OpenViking | #996 |
| Unsafe archive import paths | volcengine/OpenViking | #344 |
| Stale commit-state recovery | volcengine/OpenViking | #1187 |


