Please do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting for this repository. Include:
- affected commit or release;
- reproduction steps;
- expected and observed behavior;
- potential impact;
- any proposed mitigation.
Reports involving command injection, path traversal, credential handling, known-host verification, Git transports, Python or Node package installation, FFI memory safety, and sandbox escape are especially valuable.
The maintained target is the current main branch. Historical research
documents and archived artifacts are not independently supported products.
Maintainers will acknowledge a complete report, investigate it, and coordinate a fix and disclosure timeline based on severity. Please allow a reasonable remediation period before publishing details.