Highlights
Auth Bypass: 38 prior fixes. Scrutinize any change in this area.
plugins/governance: most-fixed (5 issues). Treat as high-risk during review.
27 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Auth Bypass: Inconsistent enforcement of Virtual Key restrictions allowed requests to bypass tool-injection filters, model allowlists, and provider boundaries, leading to unauthorized tool access and routing escalation.
SSRF: Bypasses in internal IP restrictions permitted outbound requests to reach link-local addresses, cloud metadata endpoints, and private subnets via IPv6 transitions and DNS rebinding.
Auth Bypass: Lack of strict row-level filters and scope validation in data layers allowed scoped users to enumerate and access Virtual Keys and routing rules of other tenants.