Skip to content

Security: valtors/vault

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

  1. Do not open a public GitHub issue.
  2. Email tamish@megallm.io with a description of the vulnerability and steps to reproduce.
  3. You will receive a response within 48 hours.

Scope

The following are in scope:

  • Remote code execution
  • Privilege escalation
  • Sandbox escapes
  • Data exfiltration via MCP tool calls
  • Injection attacks (prompt injection, command injection)

The following are out of scope:

  • Denial of service via resource exhaustion
  • Social engineering
  • Physical attacks

Disclosure

We follow coordinated disclosure. After a fix is released, we will publish a security advisory on GitHub.

There aren't any published security advisories