Description

### Summary A paired node could supply Unicode-confusable `platform` or `deviceFamily` metadata that passed metadata pinning but classified differently for command policy resolution, broadening default node command allowlists. ### Impact This is a policy-bypass issue within the paired-node trust boundary and can expand node command availability beyond intended defaults. ### Fix Node metadata canonicalization was hardened against confusables, and unknown platform defaults were made conservative (excluding `system.run` and `system.which` unless explicitly allowlisted). ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`

Description source: GitHub Advisory

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2026.3.1 · Fixed in 2026.3.1affected

References

2