Only the latest release receives security fixes.
Please do not open a public issue for security problems. Instead, report them privately through GitHub's security advisory feature for this repository.
Include:
- a description of the issue and its impact,
- a minimal reproducing
.ccplprogram or command, - the compiler version (
coolc --version) and your Windows version.
We will acknowledge reports as quickly as possible and keep you informed of the fix.
CCPL compiles untrusted source and generates C code that is handed to TinyCC. If
you find a way for a .ccpl program to escape the intended sandbox (for example,
by injecting arbitrary C through the code generator), that is a vulnerability and
we want to hear about it.