| Version | Supported |
|---|---|
| 0.1.x | Yes |
Please do not file a public GitHub issue for security vulnerabilities.
Report vulnerabilities using GitHub's private security advisories:
- Go to https://github.com/ctok-cli/ctok/security/advisories/new
- Fill in:
- Description of the issue
- Steps to reproduce
- Potential impact
- Any suggested mitigations
If you cannot use GitHub advisories, email kp587372@gmail.com with the same details and [ctok security] in the subject.
You will receive an acknowledgement within 48 hours. We aim to release a fix within 14 days for high-severity issues.
In scope:
@ctok/cli- command injection, path traversal, credential exposure@ctok/mcp- prompt injection via tool arguments@ctok/web- XSS, CSP bypass@ctok/browser-ext- content script injection, cross-origin data leakage@ctok/desktop- Tauri IPC abuse, privilege escalation
Out of scope:
- Issues in third-party dependencies (report to the upstream project)
- Issues requiring physical access to the device
- Social engineering
ctok collects no telemetry by default. When telemetry is opted in, only anonymous event names, app version, and platform are sent - never prompt content, file names, or any personally identifiable information.