OpenClaw 发布测试版:记忆系统支持多模态索引,修复高危管理员权限劫持漏洞

Gate News 消息,3 月 12 日,开源 AI 智能体平台 OpenClaw 于 3 月 11 日发布 v2026.3.11-beta.1 测试版,包含 15 项新功能和大量安全修复。记忆系统首次支持多模态索引,用户开启后可对本地图片和音频文件建立可搜索的向量索引,底层依赖谷歌 Gemini embedding-2-preview 嵌入模型,支持自定义输出维度,维度变更时自动触发重新索引。本地模型体验方面,新版为 Ollama 加入一站式引导流程,支持「纯本地」和「云端 + 本地」两种模式,内置推荐模型列表。iOS 端新增带实时智能体状态概览的欢迎页,浮动控件替换为底部固定工具栏;macOS 端新增聊天模型选择器。安全方面,本版修复了高危 WebSocket 劫持漏洞(GHSA-5wcw-8jjv-m286),在 trusted-proxy 模式下,攻击者可绕过浏览器来源验证获取 operator.admin 管理员权限。此外还修复了沙箱临时文件逃逸、会话重置越权访问、未认证插件路由继承管理员权限、子智能体权限提升等多个安全问题。

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Commento
0/400
Nessun commento