This project is a self-hosted assistant and handles credentials, tokens, and local automation actions. Security reports are treated as high priority.
Please do not post exploit details in a public issue.
Recommended process:
- Open a GitHub issue with title prefix
[SECURITY]and minimal details. - Request a private reporting channel in that issue.
- Share reproduction steps, impact, and affected version privately.
Include:
- Affected file(s) or endpoint(s)
- Reproduction steps
- Expected vs actual behavior
- Potential impact
- Suggested fix (optional)
- Initial acknowledgement target: 72 hours
- Triage and severity assessment target: 7 days
- Fix timeline depends on severity and exploitability
Please allow maintainers time to prepare and ship a fix before public disclosure.