Report security issues privately via a GitHub security advisory. Please do not open a public issue for a suspected vulnerability.
We aim to acknowledge reports within 5 business days. Please include the affected version (see RELEASE-INFO.txt), reproduction steps, and impact.
- The bridge binds to
127.0.0.1and makes no outbound calls. A report that model data leaves the workstation is in scope. JGS_V1_WRITE_SECRETgates write-tier elevation, and licences are validated offline against an Ed25519 public key (tools/verify_licence.py). Weaknesses in the write gate or licence validation are in scope.- The plugin JAR runs inside CATIA Magic with the user's privileges. Escalation through plugin HTTP endpoints is in scope.
Non-security questions: open an issue, or contact support@jgsystemsconsulting.com.