The official source reports this update: v1.107.7 (2026-09-29). 🛡️ Security A maintenance release for the v1 line, carrying the v1 backport of the security fix released in 2.52.0 . See the advisory for full details and affected versions. GHSA-v36g-jcw9-x7cw (moderate): converting attacker-controlled HTML with deeply nested elements in the local web_fetch tool could consume excessive CPU and memory. Provider-native web fetching is not affected. Reported by @SounLabs . ( #8985 ) Patched in 1.107.7 ; also patched on the v2 line in 2.52.0 .
Canonical AI event
Security fix for HTML processing in v1.107.7
A security fix in v1.107.7 addresses excessive CPU and memory use in the local web_fetch tool. The bug was reported by @SounLabs.
30 Sept 20261 verified claims1 sources1 observations
This official update documents a development concerning v1.107.7 (2026-09-29). Its practical significance depends on the scope and evidence stated by the source.
Read the official source update and verify its stated scope, evidence and timing before acting on it.
Connected knowledge
Entities affected by this event
Continue this topic
Related verified updates
Evidence trail
Sources behind the event
Editorial presentation
Open story