Only the latest release of dshan receives fixes. The plugin talks to a local DSH server on 127.0.0.1 and never accepts remote connections by itself; the security boundary for agent actions is your DSH configuration (sandbox policy, approval policy, skills), which dshan does not modify.
If you discover a vulnerability, please report it privately instead of opening a public issue:
- GitHub: open a private security advisory at https://github.com/Paraso42/dshan/security/advisories/new
Please include the affected version, a description, and (when available) a minimal reproduction. We will acknowledge within 7 days and keep you informed as the report is triaged and fixed.