Reporting Vulnerabilities
Two ways to report:- GitHub Security Advisories (preferred) — Create a private advisory. Only maintainers can see it until a fix is released.
- Email — Send details to security@fim.ai with a description, reproduction steps, affected versions, and impact assessment.
security label.
Response Timeline
Scope
In scope
- Authentication and authorization bypass
- SQL injection, command injection, or code execution
- Cross-site scripting (XSS) or cross-site request forgery (CSRF)
- Credential or API key exposure
- Privilege escalation between users or organizations
- Data leakage across tenant boundaries
Out of scope
- Vulnerabilities in third-party dependencies (report upstream; we monitor via Dependabot)
- Social engineering attacks
- Denial of service (DoS) without a realistic attack vector
- Issues in the demo/cloud environment that don’t affect self-hosted deployments