Only the latest release receives security updates.
Vargos handles API keys, auth tokens, and personal data. If you discover a security issue, please report it responsibly:
- Do not open a public issue.
- Use GitHub Security Advisories to file a private report.
- Include steps to reproduce if possible.
- We will respond within 48 hours.
- API key leakage in logs or error messages
- Authentication bypass in gateway or channels
- Path traversal in file operations
- Remote code execution via webhooks or MCP
- Credential exposure in config or sessions
- Whitelist (
channel.allowFrom) bypass — sending agent commands as a non-allowed user - Persona file (
~/.vargos/agents/<id>.md) injection that bypasses configuredallowedTools
- Dependency vulnerabilities (open a regular issue instead)
- Denial of service via rate limiting (this is expected behavior)
- Social engineering attacks against the user