We take the security of Cratery and our sandboxed code execution infrastructure seriously.
If you discover a security vulnerability, authentication bypass, data leak, or code execution escape:
- Do NOT open a public GitHub issue.
- Report the vulnerability privately via GitHub Private Vulnerability Reporting or email
contact@cratera.org. - Include detailed steps to reproduce, environment information, and proof-of-concept (PoC) if applicable.
We acknowledge security reports within 24 hours and prioritize fast remediation and coordinated disclosure.