Skip to content

Security: ToBeWin/openmarkdown

Security

SECURITY.md

Security Policy

Supported Version

  • 1.x receives security updates.

Reporting a Vulnerability

Please report vulnerabilities privately first.

Include:

  • affected component
  • reproduction steps
  • impact assessment
  • suggested mitigation (if available)

Do not open a public issue for unpatched critical vulnerabilities.

Scope Priorities

  1. Plugin host isolation and permission bypasses
  2. Command injection in MCP / plugin execution
  3. Local data exposure in RAG and file engine
  4. Remote API credential leakage

There aren’t any published security advisories