PulseAugur
EN
LIVE 16:14:08

redb 3.6.0 release fixes critical cross-conversation data leak

A bug report in the redb query provider revealed a critical cross-conversation leak affecting six different database providers, including Postgres, MSSql, and SQLite. The issue, present in version 3.6.0, caused user data from one conversation to be incorrectly loaded and written into another, effectively merging transcripts globally in multi-user deployments. The fix involved correcting how query roots and leaves were seeded. Additionally, a separate security vulnerability was identified where a tool could receive an exchange without proper request context, potentially allowing prompt injection if user IDs were passed as model arguments. AI

IMPACT Fixes a critical data leak in a chat product's LLM connector, improving data privacy and security for users.

RANK_REASON This is a bug fix and security update for a specific software library, not a major industry event.

Read on dev.to — LLM tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

redb 3.6.0 release fixes critical cross-conversation data leak

COVERAGE [1]

  1. dev.to — LLM tag TIER_1 English(EN) · rinat kozin ·

    redb 3.6.0: a bug report that turned out to live in six providers — plus AS2/EDI and a shared port

    <p><a class="article-body-image-wrapper" href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fs5te2rgut3a3menosvrc.png"><img alt="redb ecosystem" …