cavi-ai/
GitHub ↗

Reporting vulnerabilities

Report security issues privately. Do not open public GitHub issues for vulnerabilities that could put operators or end users at risk.

Preferred channel and response expectations are documented in SECURITY.md in the repository root.

Include:

  • Affected version / commit
  • Reproduction steps (loopback-only if possible)
  • Impact (auth bypass, capability escalation, secret leakage, …)

See also the security model summary.