fix(deps): upgrade aiohttp to 3.13.4 to remediate CVE-2026-34513 and CVE-2026-34515 #1579

Merged
HAL9000 merged 1 commits from fix/dependency-security-aiohttp-cves into master 2026-05-05 02:52:23 +00:00
+10
View File
@@ -5,6 +5,16 @@ The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
## [Unreleased]
### Security
- **aiohttp upgraded to >=3.13.4 to remediate CVE-2026-34513 and CVE-2026-34515** (#1549, #1544):
Added an explicit `aiohttp>=3.13.4` dependency constraint to `pyproject.toml` to remediate
two high-severity open redirect vulnerabilities. Both CVEs affect the CleverAgents platform's
HTTP infrastructure including A2A server communication, tool source fetching (MCP servers,
Agent Skills), and agent-to-agent protocol handlers. The version floor ensures vulnerable
versions (<3.13.4) cannot be installed even if upstream transitive dependencies have loose
version constraints.
### Changed
- Restored `benchmark-regression` CI job to `master.yml` with `pull_request` trigger guard