Sunday, September 20, 2026
1 change · master
Security fixes and vulnerability patches
VoIP call summaries now use a stronger AI model and clearer input handling to reduce cases where internal AI instructions appeared in customer-facing summaries. The change also helps protect summaries from being manipulated through call transcript content, improving trust and safety for users.
Original PR description
[IMP] voip_ai: use higher model & steer VoIP call summarizer prompt On short transcripts (e.g., "Test 41, 42, 43.") or empty/silent metadata (e.g., "WEBVTT"), the Call Summarizer agent occasionally…
[IMP] voip_ai: use higher model & steer VoIP call summarizer prompt On short transcripts (e.g., "Test 41, 42, 43.") or empty/silent metadata (e.g., "WEBVTT"), the Call Summarizer agent occasionally leaked its entire internal reasoning and chain-of-thought rules directly into the final summary field. Undelimited inputs also exposed the system to speaker-level prompt injection attacks. Since probabilistic model reasoning cannot is difficult to be entirely blocked at the API level (as some providers disregard schema maxLength bounds), this commit addresses these issues by switching to the more advanced group of models as well as steering the summarization by prompt engineering. task-6518594 [IMP] voip_ai: use higher model & steer VoIP call summarizer prompt On short transcripts (e.g., "Test 41, 42, 43.") or empty/silent metadata (e.g.,"WEBVTT"), the Call Summarizer agent occasionally leaked its entire internal reasoning or its chain-of-thought rules directly into the final summary field. An experiment was ran, it revealed that smaller models tend to output aforementioned artefacts, switching to bigger model should limit this issue. Additionally, enclose transcripts passed to llm with xml-tags, experiments showed that this limits the erroneous outputs. task-6518594 Related experiment: https://gist.github.com/nd-dew/eb89253f947387b2e85ec0dd442a9b77 Forward-Port-Of: odoo/enterprise#129670