Please report potential security vulnerabilities through OpenAI's coordinated vulnerability disclosure process. For questions about that process, contact disclosure@openai.com.
Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
When reporting a potential vulnerability, please include:
- The affected package or product and version, release artifact, or source commit.
- A clear description of the potential impact.
- Sanitized reproduction steps or a minimal proof of concept.
- Relevant runtime, environment, and known mitigations, when applicable.
Do not include live credentials, API keys, customer data, or unredacted sensitive logs.
This policy covers this repository and the official
openai npm package, including its
published release artifacts. Identify the affected SDK version or release; for
supported Node.js versions, see
NODE_VERSION_POLICY.md.
Please give the maintainers a reasonable opportunity to investigate and address the issue before public disclosure.
Thank you for helping us keep this SDK and the systems it interacts with secure.