Please report suspected vulnerabilities through GitHub's private vulnerability reporting for this repository:
https://github.com/jonfairbanks/local-rag/security/advisories/new
If private reporting is unavailable, open a GitHub issue and avoid including exploit details, private data, credentials, or sensitive local files in the public report.
Security reports are reviewed as soon as practical, with an initial response target of 14 days or less. Confirmed medium, high, or critical vulnerabilities are prioritized for a fix and release.
The project currently supports the latest released version. Users should upgrade to the newest GitHub release when security fixes are published:
https://github.com/jonfairbanks/local-rag/releases
Reports are most useful when they include:
- The affected Local RAG version or commit.
- The operating system and deployment method.
- Clear reproduction steps.
- The expected and actual security impact.
Do not include sensitive documents, private repository contents, model prompts containing secrets, or local credentials in reports.