Threadbase controls local AI coding-agent sessions, so security matters.
Please report security issues privately. Do not open public GitHub issues for vulnerabilities.
Please report privately if you find issues involving:
- API key leaks,
- pairing-token bypasses,
- unauthorized streamer access,
- WebSocket authentication issues,
- remote session control,
- command/input injection,
- unsafe local-network exposure,
- local privilege escalation,
- credential storage issues,
- push notification token handling,
- CORS/authentication bypasses.
Please email:
Include:
- affected repository,
- affected version or commit if known,
- reproduction steps,
- expected impact,
- suggested fix if you have one.
Please avoid including sensitive secrets, real API keys, or private session content in the report.
Please give reasonable time to investigate and fix the issue before public disclosure.
Security fixes may be coordinated across several Threadbase repositories.