| Version | Supported |
|---|---|
| 6.0.x | β Active development |
| 5.6.x | π Security fixes only |
| < 5.6 | β End of life |
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, please report them privately via email:
π§ security@labs.ai
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any suggested fix (optional but appreciated)
| Stage | Timeline |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial triage | Within 7 days |
| Status update | Every 14 days until resolved |
| Fix release | Depends on severity (critical: ASAP, high: 30 days, medium: 90 days) |
We follow coordinated disclosure:
- You report the vulnerability privately
- We acknowledge and begin working on a fix
- We release the fix and publish a security advisory
- You may publish your findings after the fix is released
We will credit you in the security advisory unless you prefer to remain anonymous.
- EDDI core application (
labsai/eddiDocker image) - MCP server implementation
- REST API endpoints
- Authentication and authorization mechanisms
- Official Docker images on Docker Hub
- Secrets vault implementation
- SSRF protection mechanisms
- Third-party LLM API vulnerabilities (OpenAI, Anthropic, etc.)
- User configuration errors (e.g., running without authentication)
- Vulnerabilities in dependencies (report upstream; we monitor via Dependaagent)
- Social engineering attacks
- Denial of service via expected API usage
- Never commit API keys, tokens, or passwords
- Use Vault references (
${vault:key-name}) for sensitive configuration - All external URL access must use
UrlValidationUtils.validateUrl() - No
eval(),ScriptEngine, or dynamic code execution - No
@JsonTypeInfo(use=Id.CLASS)for untrusted payloads - Read the Security documentation before contributing security-sensitive code
- Security Architecture β SSRF protection, sandboxed evaluation, tool hardening
- Secrets Vault β Secure secret storage and retrieval
- Project Philosophy β Pillar 4 β Security as Architecture