Please do not report security vulnerabilities through public GitHub issues.
Instead, use GitHub's private vulnerability reporting feature at:
https://github.com/millsydotdev/CEO-in-a-Box/security/advisories
You should receive a response within 48 hours. If you don't, please follow up via the same channel.
- Unauthorised access to user data
- Remote code execution in the plugin runtime
- Privilege escalation via organisational entities
- Exposure of secrets, tokens, or credentials
- Code injection in engine evaluation paths
| Version | Supported |
|---|---|
| Latest npm release | ✅ |
| Development builds |
- You submit a private vulnerability report
- We acknowledge receipt within 48 hours
- We investigate and develop a fix
- We release a patched version
- We disclose the vulnerability after the fix is available
We prefer all communications in English.