Security fixes should target the active development line:
develop
Feature branches may contain in-progress work and are not treated as supported release lines.
Do not open public GitHub issues for security-sensitive reports.
Instead:
- Use GitHub private vulnerability reporting for this repository:
https://github.com/seraph-quest/seraph/security/advisories/new - If that form is unavailable, email
nat@neurion.aiwith the affected branch, commit, environment details, impact, and reproduction steps. - Give the maintainers reasonable time to confirm and prepare a fix before public disclosure.
Seraph currently includes:
- a backend service with tool execution and approval paths
- workflow and MCP integration surfaces
- a browser operator workspace
- an optional native macOS daemon
Reports involving credential handling, tool boundaries, approval bypasses, sandbox escapes, secret leakage, or unsafe native/system actions are especially useful.