Unauthorized senders could trigger two command paths without sender authorization checks:
1. stop-like natural-language abort triggers
2. /models command output
An unauthorized sender could disrupt active sessions and view model/auth metadata that should be authorization-gated.
Sender authorization is now enforced for stop-like abort triggers and /models listings.
<= 2026.2.262026.3.1{
"github_reviewed_at": "2026-03-02T21:54:30Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-863"
],
"nvd_published_at": null,
"severity": "MODERATE"
}