Highlights
Auth Bypass: 41 prior fixes. Scrutinize any change in this area.
golem-worker-executor: most-fixed (12 issues). Treat as high-risk during review.
43 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Auth Bypass: WebAssembly guest executions can forge permission states if agent permission cards and function execution boundaries are not properly validated or if revoked cards are not actively drained.
Auth Bypass: Session-reuse vulnerabilities in OAuth2 webflows and mapping mutable usernames (instead of immutable IDs) allow attackers to hijack account credentials or recycle existing identities.
Denial of Service: Untrusted worker code can exhaust host memory, CPU fuel, and filesystem storage when execution-quota limits, oplog rate limits, or concurrent agent admission controls are missing or bypassed.