Please do not open public GitHub issues for security problems.
Instead, report the issue privately to the maintainers with:
- a short summary of the issue
- impact
- steps to reproduce
- affected versions or commit range
- any suggested mitigation
- We will try to confirm receipt quickly.
- We may ask for more details or a proof of concept.
- Once validated, we will work on a fix and coordinate disclosure timing.
Relevant issues include, for example:
- Electron security boundary problems
- preload or IPC exposure issues
- unsafe command execution paths
- insecure file handling or export behavior
- secrets or credential exposure