The bug was assigned CVE-2025-2135, and we successfully used it to pwn Google’s V8CTF as a zero-day. The root cause lies in TurboFan’s InferMapsUnsafe() function, which fails to handle aliasing when ...
When registering a tool using an empty Zod object as inputSchema, the generated JSON schema does not include the required field. While this is valid JSON Schema, it is incompatible with OpenAI strict ...