Ciao runs locally as the current user. A vulnerability can read or write the same files and credentials that user account can access, including the Ciao workspace, vault, runtime state, and connected provider credentials.
Security fixes target the latest released version.
Report suspected vulnerabilities privately by email to the maintainer address listed in the project repository.
Please include:
- Affected version or commit.
- Steps to reproduce.
- Impact and files, credentials, or APIs that can be accessed.
- Any suggested fix or mitigation.
Do not publish exploit details until a fix or mitigation is available.