Security fixes are applied to the latest release and the current dev branch.
Older snapshots may not receive patches.
Do not open a public issue for a suspected vulnerability.
Email hello@lifbom.com with the subject
SECURITY: <short summary>. Include the affected surface, impact, reproduction
steps or proof of concept, and the commit or version when known.
You should receive an acknowledgement within five business days. Please allow a reasonable investigation and remediation window before disclosure.
- This repository and its release artifacts.
- The hosted API at
api.blob.lifbom.com. - The account website at
blob.lifbom.com.
Especially useful reports include authentication or authorization bypasses, cross-user data access, RLS failures, credential exposure, connector approval-gate bypasses, SSRF, unsafe tool execution, and actions occurring without the required user approval.
- Do not access, change, or destroy another user's data.
- Do not perform denial-of-service, spam, social engineering, or physical attacks.
- Do not run automated scans against hosted services without written permission.
- Use test accounts and the smallest proof necessary.
- If you encounter a credential, report it without using it.
Good-faith research following these rules will not be pursued by the project maintainers.