From 327c443da67605946f34f2f7f81fc2b2b4ef8dc1 Mon Sep 17 00:00:00 2001 From: Aakash Suresh Date: Sat, 5 Sep 2026 02:28:51 -0700 Subject: [PATCH] docs: add SECURITY.md with a private reporting path MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Closes #407. The reporter of #404 looked for a confidential channel before filing a network-exposure finding, found none — no SECURITY.md, private vulnerability reporting disabled — and filed publicly because the severity happened to be low. The next finding may not be. Points at GitHub's private advisory flow, which needs no infrastructure on either side, and states scope concretely rather than generically: the unauthenticated ZMQ embedding servers, the MCP stdio transport, the document readers that handle untrusted input by design, on-disk index metadata, and third-party credentials. Note: the advisory link only works once **Settings → Security → Private vulnerability reporting** is enabled. That toggle is a repository setting, not something a PR can change. Co-Authored-By: Claude Opus 5 --- SECURITY.md | 58 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 58 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..76c580cb --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,58 @@ +# Security Policy + +## Reporting a vulnerability + +**Please do not open a public issue for a security problem.** + +Report it privately through GitHub: +[**Report a vulnerability**](https://github.com/StarTrail-org/LEANN/security/advisories/new) +(repository → **Security** → **Advisories** → *Report a vulnerability*). + +That opens a private advisory visible only to you and the maintainers. It needs +no infrastructure on either side, and it gives us a place to discuss a fix and +issue a CVE if one is warranted. + +If the advisory form is unavailable to you, open a public issue containing only +that you have a security report and how to reach you — no details — and a +maintainer will arrange a private channel. + +## What to include + +The more of this you can provide, the faster a fix lands: + +- what an attacker can achieve, and what access they need to start +- affected versions, and the platform and Python version you saw it on +- a reproduction — a script, or the commands you ran +- anything you already know about the cause or a possible fix + +## Scope + +LEANN runs locally and is usually pointed at a user's own data, so the +interesting boundaries are the ones where it stops being local: + +- the backend embedding servers, which speak an **unauthenticated ZMQ REP + protocol** — they bind `127.0.0.1` by default, and anything that can reach + the port can request embeddings (see + [Embedding Server Bind Address](docs/configuration-guide.md)) +- the MCP server and its stdio transport +- document readers and parsers, which handle untrusted input by design +- index and metadata files written to disk, and anything that reads a path out + of them +- credentials for third-party providers — API keys, endpoints, tokens + +Out of scope: findings against a deployment you have deliberately exposed to a +network (for example `LEANN_EMBEDDING_SERVER_HOST=0.0.0.0` reachable from the +internet), and vulnerabilities in third-party dependencies that are already +public — please report those upstream, though we do want to know if LEANN +pins an affected version. + +## Supported versions + +Fixes land on `main` and ship in the next release. If you are on an older +release, please confirm the issue reproduces on current `main` where you can. + +## Disclosure + +We will confirm receipt, keep you updated as we investigate, and credit you in +the advisory unless you would rather stay anonymous. Please give us a +reasonable window to ship a fix before disclosing publicly.