OpenClaw 发布测试版:记忆系统支持多模态索引,修复高危管理员权限劫持漏洞

Gate News 消息,3 月 12 日,开源 AI 智能体平台 OpenClaw 于 3 月 11 日发布 v2026.3.11-beta.1 测试版,包含 15 项新功能和大量安全修复。记忆系统首次支持多模态索引,用户开启后可对本地图片和音频文件建立可搜索的向量索引,底层依赖谷歌 Gemini embedding-2-preview 嵌入模型,支持自定义输出维度,维度变更时自动触发重新索引。本地模型体验方面,新版为 Ollama 加入一站式引导流程,支持「纯本地」和「云端 + 本地」两种模式,内置推荐模型列表。iOS 端新增带实时智能体状态概览的欢迎页,浮动控件替换为底部固定工具栏;macOS 端新增聊天模型选择器。安全方面,本版修复了高危 WebSocket 劫持漏洞(GHSA-5wcw-8jjv-m286),在 trusted-proxy 模式下,攻击者可绕过浏览器来源验证获取 operator.admin 管理员权限。此外还修复了沙箱临时文件逃逸、会话重置越权访问、未认证插件路由继承管理员权限、子智能体权限提升等多个安全问题。

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

Monad Co-Founder Suggests Dynamic Caps on Collateral Deposits to Mitigate Hacking Risks

Keone Hon suggests that pooled lending protocols should implement gradual rate limits on collateral asset increases to mitigate risks during hacks. He argues this could have prevented significant losses, as seen with rsETH depositors.

GateNews3h fa

SGB Launches USDC Mint Service on Solana Network

SGB enables instant USDC minting and redemption on Solana, improving cross-border payments with real-time settlement. Service targets institutions, removing intermediaries and supporting 24/7 liquidity and treasury management. Expansion plans include more stablecoins and retail access, li

CryptoFrontNews4h fa

Morpho Pauses MORPHO OFT Cross-Chain Bridge on Arbitrum Following Kelp DAO and LayerZero Events

Morpho Association has temporarily suspended the OFT cross-chain bridge for MORPHO tokens on Arbitrum due to recent issues with Kelp DAO and LayerZero Bridge, pending confirmation of the rsETH incident's cause.

GateNews4h fa

Spark Protocol's January delisting of rsETH proves prudent as Aave faces ETH liquidity crisis

Spark Protocol's strategy of delisting low-usage assets and tightening collateral has faced initial backlash but proved wise during market turmoil. While maintaining higher interest rate caps, SparkLend ensures liquidity, unlike Aave, which now faces significant risks.

GateNews7h fa

Kamino Pauses LayerZero-Related Asset Interactions, Closes Deposit and Lending Functions

Kamino has temporarily suspended interactions with LayerZero-related tokens as a precaution, while allowing withdrawals and debt repayments. They emphasize that this measure is for risk management and that user funds are safe.

GateNews8h fa

Aave Core Member Marc Zeller Proposes End to ACI Frontier Project, Plans to Exit Validator Role

Marc Zeller of Aave announced his proposal to end the Aave-Chan Initiative Frontier project. He will exit his validator roles, return ETH to protect wETH depositors, and forgo potential income to minimize user impact. Zeller has significantly influenced Aave's incentive mechanisms and plans to exit Aave in July.

GateNews9h fa
Commento
0/400
Nessun commento