Security fixes are applied to the latest released version and to main. Please
upgrade to the latest release before reporting an issue that may already be
fixed.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting so the maintainers can investigate before details are disclosed.
Include the affected version, configuration, reproduction steps, expected impact, and any suggested mitigation. Remove credentials, tokens, and personal data from the report.
Reports involving sandbox escape, authorization bypass, credential exposure, MCP trust boundaries, unsafe command execution, or supply-chain compromise are especially useful. We will acknowledge the report when it is triaged and keep the reporter informed as a fix and coordinated disclosure plan are developed.