Core Lightning Releases Urgent Security Update Amid Rise in AI-Generated Vulnerability Reports
A new security update has been released for Core Lightning nodes, urging immediate upgrades to fix multiple vulnerabilities. The update, version 26.06.7, was made available after a surge in AI-generated vulnerability reports targeting open-source Bitcoin projects.
The development team received and triaged several vulnerability reports from multiple sources before resolving the issues and compiling the emergency point release. In order to prevent attackers from exploiting unpatched nodes, technical details and source code will remain under embargo for 14 days.
Core Lightning advised node runners not to wait for Docker images, as they were unavailable at the time of the release. The upgrade process requires downloading and verifying the appropriate platform tarball, unpacking it over the existing installation, and restarting lightningd.