Maintainers urge operators to take CLN nodes offline until the update
The maintainers of Core Lightning (CLN), Blockstream’s Lightning implementation, reported several vulnerabilities in the software. Developer Calle urged operators to shut down CLN nodes and wait for an emergency update.
AI-based CVE reports disclosed the issues. At the time of publication, the team was preparing signed binaries and hoped to distribute a fix within 48 hours, with full disclosure within two weeks.
Murch wrote that operators should consider taking nodes offline, cutting communications with other Lightning nodes. No loss of funds or active exploitation of the issue has been reported so far.





