> This page is for Itential Platform On-Prem, version 6 (default).
> For other versions, use one of these documentation indexes:
> - 6 (default): https://docs.itential.com/itential-platform/6/llms.txt
> - 2023.2: https://docs.itential.com/itential-platform/2023-2/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# 6.6.0

Platform 6.6.0 is a minor release that adds validation APIs across Platform components, expands audit logging, and introduces a rich text editor for Agent Prompts. This release also includes security updates, bug fixes, and enhancements across Core, Gateway Manager, Integrations, Work Center, and NSO Service Manager.

For more information on new features introduced in this release, see [Platform 6.6 feature announcement](/itential-platform/release-notes/feature-announcements/660).

#### Enhancements (21)

| Component                        | Feature                                                                          | Description                                                                                                                                                                                                                                                                      |
| -------------------------------- | -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Agent Projects                   | **Rich text editor for Agent Prompts** (ENG-27470)                               | Replaced the plain text editor in Agent Prompts with a rich text editor.                                                                                                                                                                                                         |
| Configuration Manager            | **Golden configuration validation API** (ENG-26750)                              | Added a validation API for golden configurations and improved validation checks when you create or update them.                                                                                                                                                                  |
| Core                             | **Audit logging for authorization, service, and Studio resources** (ENG-27886)   | Added audit logging for authorization, service, and Studio resources.                                                                                                                                                                                                            |
| Core                             | **Platform encryption key rotation script** (ENG-27147)                          | Added a script to rotate Platform encryption keys.                                                                                                                                                                                                                               |
| Core                             | **Audit logging capabilities** (ENG-26769, ENG-27172)                            | Enabled `log.audit` capabilities in services and Platform.                                                                                                                                                                                                                       |
| Core                             | **Web server metrics endpoint** (ENG-25533)                                      | Added an OpenTelemetry-compatible `/metrics/webserver` endpoint that exposes web server request, error, and latency metrics for monitoring and observability.                                                                                                                    |
| Gateway Manager                  | **Delete dialog styling for certificates** (ENG-28165)                           | Improved the styling of the delete dialog for Gateway Manager certificates.                                                                                                                                                                                                      |
| Gateway Manager                  | **Virtual cluster load balancing** (ENG-27425)                                   | Made minor improvements to load balancing for virtual clusters.                                                                                                                                                                                                                  |
| Gateway Manager                  | **Resource payload validation API** (ENG-26751)                                  | Added a validation API endpoint that checks resource payloads before you create them. Also improved validation on the create and update endpoints to reject invalid or dangerous payloads more reliably.                                                                         |
| Configuration Manager Enterprise | **JSON compliance reports written to GridFS** (ENG-27199)                        | Large JSON compliance reports are now written to GridFS.                                                                                                                                                                                                                         |
| Configuration Manager Enterprise | **Device compliance reports written to GridFS** (ENG-27198)                      | Large device compliance reports are now written to GridFS.                                                                                                                                                                                                                       |
| Inventory Manager                | **Semantic validation for inventory documents** (ENG-26749)                      | Added semantic validation for inventory, node, action, and tag documents. Validation runs automatically on create and update. You can also check a draft before saving with the new `POST /v1/validate` endpoint. This ensures FlowAI builder skills persist only valid changes. |
| MOP                              | **MOP validation API** (ENG-26773)                                               | Added a validation API that verifies the form and shape of templates using backend and frontend logic.                                                                                                                                                                           |
| Operations Manager               | **componentType required with componentId or componentName** (ENG-26443)         | Operations Manager now requires `componentType` whenever you set `componentId` or `componentName`.                                                                                                                                                                               |
| Operations Manager               | **GBAC read-requires-write on createAutomation** (ENG-26442)                     | Enforced the GBAC read-requires-write rule on `createAutomation`.                                                                                                                                                                                                                |
| Operations Manager               | **Validation for componentName-only automation updates** (ENG-26441)             | Added validation for automation updates that set only `componentName`.                                                                                                                                                                                                           |
| Operations Manager               | **Manual trigger validation** (ENG-26440)                                        | Operations Manager now validates manual trigger `formId` and `formData` at write time.                                                                                                                                                                                           |
| Studio                           | **Transformation validation API** (ENG-26772)                                    | Added a validation API for transformations.                                                                                                                                                                                                                                      |
| Studio, Workflow engine          | **Keys with reserved characters** (ENG-27145)                                    | Added support for resolving keys that contain `?`, `(`, `[`, or `{`. Platform no longer treats these characters as reserved.                                                                                                                                                     |
| Templates                        | **Template validation API** (ENG-26793)                                          | Added a validate template API endpoint that checks the structure of a template using frontend and backend rules.                                                                                                                                                                 |
| Workflows                        | **Deep validation option for workflow import** (ENG-27588, ENG-27589, ENG-27590) | Added an option to the import workflows API call for deep validation. Validation now warns when the `position` field is missing.                                                                                                                                                 |

#### Bug fixes (44)

| Component                               | Feature                                                                             | Description                                                                                                                                                                                                                                                                                                                                                 |
| --------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Core                                    | **Stale adapter method and task configurations** (ENG-27920)                        | Fixed an issue where restarting an adapter left Platform showing outdated method and task configurations.                                                                                                                                                                                                                                                   |
| Core                                    | **exportService and exportProfile errors** (ENG-27543)                              | Fixed an issue where `exportService` and `exportProfile` always threw an error instead of returning a result.                                                                                                                                                                                                                                               |
| Core                                    | **Duplicate service fork** (ENG-27333)                                              | Fixed a race condition that could fork a service twice and leave an untracked duplicate process when a restart, start, or reboot overlapped with another operation on the same service.                                                                                                                                                                     |
| Core                                    | **Missing views property in pronghorn.json** (ENG-27329)                            | Fixed an issue where a missing `views` property in a `pronghorn.json` file caused UIs to crash with a "Something Went Wrong" message.                                                                                                                                                                                                                       |
| Core                                    | **MongoDB oplog growth in looped workflows** (ENG-27251)                            | Fixed excessive MongoDB oplog growth in looped workflows.                                                                                                                                                                                                                                                                                                   |
| Core                                    | **OpenAPI 3.0 import rejected for boolean exclusiveMinimum** (ENG-26838)            | Fixed an issue where OpenAPI 3.0 integration imports were rejected when `exclusiveMinimum` was a boolean.                                                                                                                                                                                                                                                   |
| Core                                    | **Integration worker memory leak** (ENG-26833)                                      | Fixed a slow memory leak in the Integration worker. Per-request loggers left behind an exception handler, which caused memory use to grow over the life of a long-running process.                                                                                                                                                                          |
| FlowAI                                  | **Tool discovery failure isolation** (ENG-27678)                                    | Tool discovery now isolates a failure to the specific tool that failed instead of blocking the whole collection.                                                                                                                                                                                                                                            |
| FlowAI, Operations Manager, Work Center | **Redis rolling restart handling** (ENG-26590)                                      | Fixed how FlowAI, Operations Manager, and Work Center handle a Redis rolling restart.                                                                                                                                                                                                                                                                       |
| Gateway Manager                         | **Stale text in delete confirmation dialogs** (ENG-28154)                           | Fixed an issue where Gateway delete confirmation dialogs displayed stale text.                                                                                                                                                                                                                                                                              |
| Gateway Manager                         | **Gateway certificate toggle** (ENG-27564)                                          | Fixed a UI issue when toggling Gateway certificates.                                                                                                                                                                                                                                                                                                        |
| Integrations                            | **Bare string responses with dynamic retrieval** (ENG-28568, ENG-29247, ENG-28969)  | Fixed authentication and Gateway-routed requests for integration models that use `x-itential-dynamic-retrieval` with a bare string response.                                                                                                                                                                                                                |
| Integrations                            | **Variable substitution for path-level and operation-level parameters** (ENG-27670) | Fixed OpenAPI integration variable substitution so `x-itential-variable` values declared on path-level or operation-level parameters are injected into outgoing requests.                                                                                                                                                                                   |
| Integrations                            | **Oversized OpenAPI model import** (ENG-27378)                                      | Fixed an issue where importing an OpenAPI integration model over 15 MB could succeed despite a warning. Platform now rejects oversized models with a clear error message.                                                                                                                                                                                   |
| Integrations                            | **AWS Signature v4 with non-standard hostnames** (ENG-27372)                        | Added support for explicitly declaring the AWS region and service on an integration. AWS Signature v4 authentication now works with non-standard hostnames.                                                                                                                                                                                                 |
| JSON forms                              | **Dynamic dropdown 404 with special characters in adapter name** (ENG-9540)         | Fixed an issue where a JSON form dynamic dropdown returned a 404 error when the adapter it queried had a space or other special character in its name.                                                                                                                                                                                                      |
| JSON forms                              | **Form clipped when errors are present** (ENG-7534)                                 | Fixed an issue where a JSON form was visually clipped when form errors were present and you selected a radio button.                                                                                                                                                                                                                                        |
| JSON forms                              | **Add Validation tooltip** (ENG-5865)                                               | Removed the tooltip from the **Add Validation** button in the JSON form configure dialog.                                                                                                                                                                                                                                                                   |
| JSON forms                              | **Duplicate wizard step numbers** (ENG-5860)                                        | Fixed an issue where a dynamic dropdown with a JSON Schema transformation (JST) source and a field dependency displayed two wizard steps numbered "3" instead of "3" and "4".                                                                                                                                                                               |
| JSON forms                              | **Dynamic dropdown API display** (ENG-5159)                                         | Fixed an issue with how dynamic dropdowns display API data.                                                                                                                                                                                                                                                                                                 |
| Lifecycle Manager                       | **Broken redirect** (ENG-10761)                                                     | Fixed a broken redirect in Lifecycle Manager.                                                                                                                                                                                                                                                                                                               |
| Lifecycle Manager                       | **Scrollbar flicker in Firefox** (ENG-5382)                                         | Fixed an issue where the scrollbar flickered in the Instance History and Instance Groups history lists in Firefox.                                                                                                                                                                                                                                          |
| MOP, Studio, Workflows                  | **Blank ID overwrote existing ID** (ENG-27183)                                      | Fixed an issue where an existing ID could be overwritten with a blank ID, which caused errors.                                                                                                                                                                                                                                                              |
| NSO Service Manager                     | **Trace context for NSO 6.3 and later** (ENG-27014)                                 | Improved trace context support for NSO 6.3 and later to provide better request tracing across additional supported methods.                                                                                                                                                                                                                                 |
| Operations Manager                      | **Browser freeze on long job ancestor chains** (ENG-29014)                          | Fixed an issue where opening the details page of a job with a very long ancestor chain froze or crashed the browser tab. An example is a recursive child job tens of thousands of levels deep. The job breadcrumb now looks up only the root job and the 10 nearest ancestors. Users without permission to view jobs no longer trigger the ancestor lookup. |
| Operations Manager, Work Center         | **Additional debug logging** (ENG-27156)                                            | Added debug logging to Operations Manager and Work Center.                                                                                                                                                                                                                                                                                                  |
| Platform                                | **Misaligned array field columns** (ENG-27614)                                      | Fixed an issue in JSON Schema Form array fields where row columns were misaligned with the column header. This happened when a schema combination (`allOf` or `if-then`) added a column for only some rows.                                                                                                                                                 |
| Projects                                | **Pagination controls hidden by banner** (ENG-28241)                                | Fixed an issue where the pagination controls on the Projects list view became inaccessible when a banner was displayed.                                                                                                                                                                                                                                     |
| Projects                                | **Add to project search filter** (ENG-4882)                                         | Fixed the filter in the add to project search dialog so it searches all documents instead of only the current page.                                                                                                                                                                                                                                         |
| Projects, Studio                        | **Empty area below tree navigation lists** (ENG-4204)                               | Fixed an issue where an empty, non-functional area appeared below the last item in some tree-based navigation lists.                                                                                                                                                                                                                                        |
| Projects, Transformations               | **JST tour popup stays visible** (ENG-13439)                                        | Fixed an issue where the JSON Schema transformation (JST) "Take a Tour!" onboarding popup stayed visible after you left the JST editor without dismissing it.                                                                                                                                                                                               |
| Studio                                  | **Run Service nested query saved to wrong field** (ENG-28436)                       | Fixed an issue where a task query on a field nested in the Run Service task's `params` object saved to a duplicate top-level field, so the task received an empty value at runtime. Queries now target the intended field.                                                                                                                                  |
| Studio, Templates, Transformations      | **In-flight work lost during restart** (ENG-26870)                                  | Fixed an issue where in-flight work in the JST transformation, MOP retry, and Template Builder services could be lost or left incomplete during a Platform restart. These services now complete or safely hand off in-flight work during shutdown.                                                                                                          |
| Transformations                         | **Multiple tabs opened on click** (ENG-27029)                                       | Fixed an issue where a transformation opened multiple tabs when you selected it.                                                                                                                                                                                                                                                                            |
| Transformations                         | **Stop method scroll reset in JST builder** (ENG-4985)                              | Fixed an issue where the Stop method scroll position reset in the JST builder.                                                                                                                                                                                                                                                                              |
| Transformations                         | **Reordering user function inputs broke mappings** (ENG-3311)                       | Fixed an issue where reordering the inputs on a user function could break existing input mappings.                                                                                                                                                                                                                                                          |
| Work Center                             | **Assignee dropdown and column** (ENG-28591)                                        | Fixed an issue where the **Assignee** dropdown didn't populate until you typed a filter, and the **Assignee** column could show a raw account ID instead of the user's name. An older account record crashed the account list lookup. The lookup now handles these records.                                                                                 |
| Workflows                               | **Task input values restored from another task** (ENG-29225)                        | Fixed an issue in the Workflow Editor where switching a task input back to **Job**, **Static**, or **Task** could restore a value from a different task's input with the same name. Platform now remembers previous values for each task and each input.                                                                                                    |
| Workflows                               | **Run Service task parameters** (ENG-28541)                                         | Fixed existing workflows with Run Service tasks that were previously modified incorrectly. The queried value is now stored correctly in the task parameters.                                                                                                                                                                                                |
| Workflows                               | **Job variable input validation** (ENG-27668)                                       | Fixed an issue where running a workflow with a task input set to a job variable with an inline query failed input validation when you provided an object or array. The workflow input schema now accepts objects and arrays for these variables.                                                                                                            |
| Workflows                               | **.xlsm upload on Windows** (ENG-26434)                                             | Fixed an issue where uploading `.xlsm` files on Windows failed.                                                                                                                                                                                                                                                                                             |
| Workflows                               | **Edit buttons shifted by long names** (ENG-14388)                                  | Fixed an issue where long names pushed the edit buttons down. The edit options now stay on the same line.                                                                                                                                                                                                                                                   |
| Workflows                               | **Duplicate x and y coordinates** (ENG-9373)                                        | Fixed an issue where an item stored more than one set of x and y coordinates. Each item now has only one set.                                                                                                                                                                                                                                               |
| Workflows                               | **Child job not run for empty loop array** (ENG-5444)                               | Platform now displays a clear message when a child job never ran because the loop array was empty.                                                                                                                                                                                                                                                          |

#### Security fixes (40)

This release includes security updates that address vulnerabilities in third-party packages and Platform components.

| Component                          | Feature                                                                                               | Description                                                                                                                                                                                                                                                                                                                  |
| ---------------------------------- | ----------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Admin Essentials                   | **Prototype pollution in Integration Model viewer** (ENG-28232)                                       | Fixed a client-side prototype pollution vulnerability (CVE-2026-93753) in the Integration Model viewer. Imported OpenAPI and Swagger documents are now sanitized to remove `__proto__`, `constructor`, and `prototype` keys before rendering. This closes a bypass in the `deepmerge` dependency, which has no upstream fix. |
| Core                               | **ReDoS in brace-expansion** (ENG-28894)                                                              | Updated `brace-expansion`, which `minimatch` uses internally for glob pattern matching, to patched versions to resolve a denial-of-service (ReDoS) vulnerability (CVE-2026-102277).                                                                                                                                          |
| Core                               | **axios vulnerability** (ENG-28881)                                                                   | Updated `axios` to resolve a security vulnerability.                                                                                                                                                                                                                                                                         |
| Core                               | **CRLF injection in form-data** (ENG-28474)                                                           | Updated `form-data` to 4.0.6 to resolve a CRLF injection vulnerability (CVE-2026-12143). The vulnerable code path isn't reachable from Platform first-party code.                                                                                                                                                            |
| Core                               | **proxy-addr vulnerability** (ENG-27978)                                                              | Overrode the `proxy-addr` dependency to resolve a known vulnerability.                                                                                                                                                                                                                                                       |
| Core                               | **moment vulnerability** (ENG-27977)                                                                  | Updated `moment` to resolve a security vulnerability.                                                                                                                                                                                                                                                                        |
| Core                               | **Memory leak in compression** (ENG-27932)                                                            | Updated `compression` to resolve a memory-leak vulnerability.                                                                                                                                                                                                                                                                |
| Core                               | **ReDoS in path-to-regexp** (ENG-27889)                                                               | Updated `path-to-regexp`, which Express uses internally, to the latest patched version to resolve a denial-of-service (ReDoS) vulnerability (CVE-2026-4867).                                                                                                                                                                 |
| Core                               | **undici vulnerability** (ENG-27496)                                                                  | Updated `undici` to resolve a security vulnerability.                                                                                                                                                                                                                                                                        |
| Core                               | **fast-uri vulnerability** (ENG-27465)                                                                | Updated `fast-uri` to resolve a security vulnerability.                                                                                                                                                                                                                                                                      |
| Core                               | **@xmldom/xmldom vulnerability** (ENG-27392)                                                          | Updated the transitive `@xmldom/xmldom` dependency to resolve a security vulnerability.                                                                                                                                                                                                                                      |
| Core                               | **js-yaml vulnerability** (ENG-27390)                                                                 | Updated `js-yaml` to resolve a security vulnerability.                                                                                                                                                                                                                                                                       |
| Core                               | **Unmaintained json-stringify-safe dependency** (ENG-26693)                                           | Replaced the unmaintained `json-stringify-safe` dependency with `safe-stable-stringify` for worker-thread message serialization and JSON Schema sanitization.                                                                                                                                                                |
| Gateway Manager                    | **Third-party dependency updates** (ENG-28266, ENG-27909, ENG-27908, ENG-27891, ENG-27890, ENG-27887) | Updated third-party dependencies to resolve security vulnerabilities.                                                                                                                                                                                                                                                        |
| Gateway Manager                    | **ws vulnerability** (ENG-27892)                                                                      | Updated `ws` to resolve security vulnerabilities.                                                                                                                                                                                                                                                                            |
| Gateway Manager                    | **HTML sanitizer vulnerability in monaco-editor** (ENG-26372)                                         | Updated `monaco-editor`, the code editor bundled with Gateway Manager, to resolve a vulnerability (CVE-2026-65898) in its embedded HTML sanitizer.                                                                                                                                                                           |
| Gateway Manager, Inventory Manager | **Third-party dependency updates** (ENG-29474)                                                        | Updated third-party dependencies to resolve security vulnerabilities.                                                                                                                                                                                                                                                        |
| Inventory Manager                  | **Third-party dependency updates** (ENG-28264, ENG-27910)                                             | Updated third-party dependencies to resolve security vulnerabilities.                                                                                                                                                                                                                                                        |
| Legacy Forms                       | **Unused wicked-good-xpath polyfill** (ENG-26695)                                                     | Removed the unused `wicked-good-xpath` polyfill from the Form Builder task path.                                                                                                                                                                                                                                             |
| NSO Service Manager                | **XSS in DOMPurify (app-service\_management)** (ENG-29479)                                            | Resolved a cross-site scripting (XSS) vulnerability by updating `DOMPurify` to a secure version in app-service\_management.                                                                                                                                                                                                  |
| NSO Service Manager                | **Double decoding in fast-uri (app-nso\_manager)** (ENG-29472)                                        | Resolved a double decoding of the same data vulnerability (CVE-2026-75899) by updating `fast-uri` to a secure version in app-nso\_manager.                                                                                                                                                                                   |
| NSO Service Manager                | **XSS in DOMPurify (app-nso\_manager)** (ENG-29463)                                                   | Resolved a cross-site scripting (XSS) vulnerability by updating `DOMPurify` to a secure version in app-nso\_manager.                                                                                                                                                                                                         |
| NSO Service Manager                | **Uncontrolled recursion in brace-expansion (app-nso\_manager)** (ENG-29457)                          | Resolved an uncontrolled recursion vulnerability (CVE-2026-102276) by updating `brace-expansion` to a secure version in app-nso\_manager.                                                                                                                                                                                    |
| NSO Service Manager                | **Case sensitivity in fast-uri (app-service\_management)** (ENG-29227)                                | Resolved an improper handling of case sensitivity vulnerability (CVE-2026-86472) by updating `fast-uri` to a secure version in app-service\_management.                                                                                                                                                                      |
| NSO Service Manager                | **Infinite loop in uri-js (app-service\_management)** (ENG-29226)                                     | Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the affected `uri-js` dependency with a drop-in replacement in app-service\_management.                                                                                                                                                                |
| NSO Service Manager                | **SSRF in axios (app-nso\_manager)** (ENG-29111)                                                      | Resolved a server-side request forgery (SSRF) vulnerability (CVE-2026-101898) by updating `axios` to 1.20.0 in app-nso\_manager.                                                                                                                                                                                             |
| NSO Service Manager                | **Infinite loop in uri-js (app-nso\_manager)** (ENG-28512)                                            | Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the affected `uri-js` dependency with a secure replacement in app-nso\_manager.                                                                                                                                                                        |
| NSO Service Manager                | **Directory traversal in Moment (app-nso\_manager)** (ENG-28511)                                      | Resolved a directory traversal vulnerability (CVE-2026-17495) by updating `moment` to a secure version in app-nso\_manager.                                                                                                                                                                                                  |
| NSO Service Manager                | **Interpretation conflict in fast-uri (app-service\_management)** (ENG-28510)                         | Resolved an interpretation conflict vulnerability (CVE-2026-84292) by updating `fast-uri` to 3.1.7 in app-service\_management.                                                                                                                                                                                               |
| Operations Manager                 | **axios vulnerability** (ENG-29405)                                                                   | Updated `axios` in Operations Manager 23.2 to resolve a security vulnerability.                                                                                                                                                                                                                                              |
| Platform                           | **Dependency updates** (ENG-28288)                                                                    | Updated Platform dependencies to resolve security vulnerabilities.                                                                                                                                                                                                                                                           |
| Studio                             | **Deprecated lodash.isequal dependency** (ENG-26696)                                                  | Replaced the deprecated `lodash.isequal` dependency with `isDeepStrictEqual` from `node:util` on the server and `equals` from `ramda` in browser-bundled code. This internal change doesn't affect user-facing behavior.                                                                                                     |
| Work Center                        | **Multiple vulnerabilities in axios** (ENG-28877, ENG-28875, ENG-28873, ENG-28871, ENG-28870)         | Updated `axios` to a patched release to resolve multiple high-severity vulnerabilities, including ReDoS, denial of service, improper input validation, and prototype pollution.                                                                                                                                              |
| Work Center                        | **Uncontrolled recursion in brace-expansion** (ENG-28739)                                             | Resolved a high-severity uncontrolled recursion vulnerability (CVE-2026-102276) in the `brace-expansion` dependency used by nestjs-platform by updating the transitive dependency to a patched version.                                                                                                                      |
| Work Center                        | **Uncontrolled recursion in backend dependency** (ENG-28731)                                          | Resolved a high-severity uncontrolled recursion vulnerability, which could cause denial of service, by updating a third-party dependency of the Work Center backend service to a patched version.                                                                                                                            |
| Work Center                        | **IP spoofing in proxy-addr** (ENG-27956, ENG-27942)                                                  | Resolved a critical vulnerability (CVE-2026-90711) in `proxy-addr`. A crafted `X-Forwarded-For` header could spoof the client IP address and bypass IP-based access control, rate limiting, geolocation, and audit logging.                                                                                                  |
| Work Center                        | **multer vulnerability** (ENG-27928)                                                                  | Resolved a vulnerability in the `multer` package.                                                                                                                                                                                                                                                                            |
| Work Center                        | **Prototype pollution in joi** (ENG-27843)                                                            | Updated `joi` in work-center-service from 18.2.3 to 18.2.9 to resolve a prototype pollution vulnerability (CVE-2026-90771).                                                                                                                                                                                                  |
| Work Center                        | **js-yaml vulnerability** (ENG-27416)                                                                 | Resolved a vulnerability in the `js-yaml` package.                                                                                                                                                                                                                                                                           |
| Work Center                        | **Nested dependency vulnerability in shared library** (ENG-27405)                                     | Resolved a vulnerability in a nested dependency of a shared library that Work Center and Agent Session Manager use.                                                                                                                                                                                                          |

#### Sub-tasks (1)

| Component           | Feature                                                             | Description                                                                                                              |
| ------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| NSO Service Manager | **Node.js 22 and npm 10 support** (ENG-27541, ENG-27540, ENG-27539) | Updated package metadata in app-service\_management, app-nso\_manager, and adapter-nso to support Node.js 22 and npm 10. |

#### Component versions

| Component                        | Version |
| -------------------------------- | ------- |
| FlowAI                           | 1.2.0   |
| Gateway Manager                  | 1.2.4   |
| Inventory Manager                | 1.2.19  |
| NSO Service Manager              | 6.6.0   |
| Configuration Manager Enterprise | 6.6.0   |