This security policy applies to the llama-forge GUI frontend (llama_gui/) and the build system maintained in this fork.
For security vulnerabilities in the upstream llama.cpp inference engine, please report directly to ggml-org/llama.cpp.
| Version | Supported |
|---|---|
Latest master |
β Yes |
| Older commits | β No |
Please do not open a public GitHub Issue for security vulnerabilities.
Report privately via email:
π§ tradeguruboffin@gmail.com
- A clear description of the vulnerability
- The component affected (
llama_gui/, build system, etc.) - Steps to reproduce
- Potential impact and severity assessment
- Any suggested fix (optional but appreciated)
| Stage | Timeline |
|---|---|
| Acknowledgement | Within 72 hours |
| Initial assessment | Within 7 days |
| Fix release (if confirmed) | Within 14 days |
We follow responsible disclosure. Please allow us time to investigate and release a fix before making any vulnerability public.
- Vulnerabilities in upstream llama.cpp (report to ggml-org)
- Issues requiring physical access to the device
- Social engineering attacks
- PyQt6 or Qt framework vulnerabilities (report to the Qt Project)