Skip to content

Security: RonenMars/threadbase

Security

SECURITY.md

Security Policy

Threadbase controls local AI coding-agent sessions, so security matters.

Please report security issues privately. Do not open public GitHub issues for vulnerabilities.


Security-sensitive areas

Please report privately if you find issues involving:

  • API key leaks,
  • pairing-token bypasses,
  • unauthorized streamer access,
  • WebSocket authentication issues,
  • remote session control,
  • command/input injection,
  • unsafe local-network exposure,
  • local privilege escalation,
  • credential storage issues,
  • push notification token handling,
  • CORS/authentication bypasses.

Reporting a vulnerability

Please email:

ronenmars@gmail.com

Include:

  • affected repository,
  • affected version or commit if known,
  • reproduction steps,
  • expected impact,
  • suggested fix if you have one.

Please avoid including sensitive secrets, real API keys, or private session content in the report.


Public disclosure

Please give reasonable time to investigate and fix the issue before public disclosure.

Security fixes may be coordinated across several Threadbase repositories.

There aren't any published security advisories