A bug report in the redb query provider revealed a critical cross-conversation leak affecting six different database providers, including Postgres, MSSql, and SQLite. The issue, present in version 3.6.0, caused user data from one conversation to be incorrectly loaded and written into another, effectively merging transcripts globally in multi-user deployments. The fix involved correcting how query roots and leaves were seeded. Additionally, a separate security vulnerability was identified where a tool could receive an exchange without proper request context, potentially allowing prompt injection if user IDs were passed as model arguments. AI
IMPACT Fixes a critical data leak in a chat product's LLM connector, improving data privacy and security for users.
RANK_REASON This is a bug fix and security update for a specific software library, not a major industry event.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →