Please use GitHub's private vulnerability reporting feature for this repository. Do not open a public issue for a suspected vulnerability.
Include the affected component, reproduction steps, expected impact, and any suggested mitigation. Do not include live credentials, private telemetry, or customer data. If evidence contains sensitive material, describe it and wait for a maintainer to provide a safe transfer method.
ThinkEx will acknowledge a report as soon as practical, investigate it, and coordinate remediation and disclosure with the reporter.
Security-sensitive areas include:
- Worker and provider credential boundaries
- Durable Object and agent routing
- investigation sandbox isolation
- repository write and draft pull-request publication controls
- public-web and provider request validation