What's Changed
Security Fixes
JS: Respect allow-local-file-access in require by @dwisiswant0 (#7332)
CVE-2026-41646 - GHSA-29rg-wmcw-hpf4
Expressions: Only evaluate template-authored expressions by @dwisiswant0 (#7221)(#7321)
CVE-2026-41645 - GHSA-jm34-66cf-qpvr
Bug Fixes
HTTP: Respect annotations in unsafe mode by @dwisiswant0...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3459685