v1.10.0
chatboxai/chatboxv1.10.0Jun 18, 2026by lfnovo
AI Summary
Introduces LaTeX math rendering, Turkish localization, and various reliability/security fixes including a security patch for CVE-2026-48710.
Key Highlights
- LaTeX math rendering in chat (KaTeX)
- Turkish (tr-TR) localization support
- Security fix: Bumped Starlette and FastAPI to address CVE-2026-48710
- Retry processing button added for failed sources
Breaking Changes
- Database migration 15 adds flexible config object on credential table
New Features
- LaTeX rendering for inline and display math
- Bulk chat-context actions for sources and notes
- OpenRouter embedding modality exposure
- Ollama num_ctx override persistence
Full Release Notes
Highlights: LaTeX rendering in chat, per-type bulk chat-context controls, Turkish UI, a security fix, and a batch of ingestion/search reliability fixes.
> **Upgrade note:** this release adds database **migration 15** (a flexible `config` object on the `credential` table), applied automatically on API startup.
## 🔒 Security
- Bumped **Starlette → 1.2.1** and **FastAPI → 0.136.3** to address **CVE-2026-48710** ("BadHost") (#859)
## ✨ Added
- **LaTeX math rendering in chat** — inline `$...$` and display `$$...$$` via KaTeX (#606)
- **Bulk chat-context actions** in the Sources and Notes column headers — sources: *insights only* / *full content* / *exclude all*; notes: *include / exclude all* — translated across all 14 locales (#223)
- **Turkish (tr-TR)** localization (#871)
- `NEXT_PUBLIC_API_TIMEOUT_MS` to configure the frontend API request timeout (#880)
## 🔧 Changed
- Prominent **"Retry processing"** button on failed source cards (#726)
- Docker base image → **Debian trixie + Node.js 22.x** (#914)
## 🐛 Fixed
- Sources that fail to ingest are now marked **`failed`** (so the retry button actually appears) instead of being saved as `completed` with the extraction error as their body (#726)
- Podcast generation now uses the notebook's real content via `Notebook.get_context()` (#864)
- `PUT` profile handlers use `model_dump(exclude_unset=True)` so partial updates don't wipe unset fields (#860)
- OpenRouter embedding modality is now exposed (#842)
- `POST /sources/{id}/retry`: no longer returns `400` for every source (#861), and no longer `500` from a double-prefixed command id
- `GET /sources/{id}` returns `404` (not `500`) for a missing or deleted source
- Text search falls back to vector search on a `search::highlight` "position overflow" (#648)
- `POST /api/search` rejects a non-positive `limit` with `422` (#863)
- Ollama `num_ctx` override is now persisted via a flexible `config` object (migration 15) (#875)
- Worker drains legacy embedding jobs via command aliases (#695, #876)
- Updated AI provider configuration docs (#873)
## ⚡ Performance
- Memoized the notebook source list and stopped polling completed sources (#503)
## 📚 Docs
- Code of Conduct (#856), local quickstart + worker step (#900), `export_docs.py` Table of Contents (#865)
## 📦 Dependencies
- Multiple dependency bumps, including **cryptography 46→48**, **langchain 1.2→1.3**, langchain-anthropic, aiohttp, tornado, and frontend dev dependencies.
## 🙌 Contributors
Thanks to everyone who shipped a PR in this release: @aaronjmars, @doganreis, @Federicorao, @fboudra, @krataratha, @ltianyi992, @mvanhorn, @royfrancis, @zichen0116, and @lfnovo.
**Full Changelog**: https://github.com/lfnovo/open-notebook/compare/v1.9.0...v1.10.0