Thanks for helping keep this project and the people using it safe 💛
Our version history is liniar, and we use semantic versioning. Only the latest release gets patched, so check you're on it before reporting anything.
There's no login. It serves whatever it can read - session ids, working directory names, model
names, the paths it reads from - to anyone who can reach the port. That's fine on the setup it
ships with (HOST=127.0.0.1), and not fine on a LAN interface or anything public. The container
binds 0.0.0.0 because it has to, so only publish that port to localhost or put it behind
something that asks who you are.
Source files are only ever read, never written. The one credential it can touch is the Claude Code OAuth token, and only while the plan windows setting is on: it goes to Anthropic and nowhere else, and is never stored or logged.
Important
Please don't report anything publicly (issues, PRs, discussions) without giving us at least 30 days to respond and handle it.
Acceptible channels:
- GitHub (preferred) - open an advisory from the Security tab
- Email - security@peng.ly (PGP:
A8431F9F332FB0CD)
Include the type of issue, the affected version and file paths, steps to reproduce, a PoC if you've got one, and what an attacker could actually achieve with it.
Keep it short, and don't over-state the impact - it's not helpful. Using AI is fine, just say that you have.
I'll try to acknowledge and triage within 48 hours. If it's valid, I'll get a fix out within 2 weeks and publish the advisory, and I'll keep you updated throughout.
Coordinated, so give us a fair chance to ship a fix before going public. Happy to credit you in the advisory and release notes, or leave you out of it - your call.
Report in good faith, stick to this policy, and steer clear of privacy violations, data destruction and service disruption, and I won't pursue or support legal action against you.