We actively maintain and provide security updates for the following versions of Gengar:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0.0 | ❌ |
The Gengar team and contributors take the security and privacy of researchers very seriously. Because Gengar interacts with Tor circuits, hidden services, and unhosted network endpoints, we prioritize prompt resolution of security vulnerabilities.
- Do not open public GitHub issues for suspected security vulnerabilities or zero-day disclosures.
- Please report vulnerabilities privately by emailing the maintainer or opening a GitHub Private Vulnerability Report.
- Provide detailed steps to reproduce the vulnerability, including:
- Affected endpoint or module
- Proof-of-concept payload or script
- Expected vs. actual behavior
- Environment details (Node.js version, OS, Docker/Local)
- We will acknowledge receipt of your vulnerability report within 48 hours.
- We will provide a timeline for assessing the severity and releasing a patch.
- We will credit reporters publicly in the release notes (unless anonymity is requested).
Gengar is built strictly for educational, authorized research, and lawful OSINT purposes. Maintaining user privacy and network integrity across Tor circuits is a core design principle.