| Version | Supported |
|---|---|
main branch |
✅ |
Please do not report security vulnerabilities via public GitHub issues.
Email moe.bouassida@gmail.com with:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept if possible)
- Any suggested mitigations
You will receive an acknowledgement within 48 hours and a resolution timeline within 7 days.
| In scope | Out of scope |
|---|---|
| API injection / prompt injection in LLM agents | Findings in third-party dependencies (report upstream) |
| Authentication bypass | Social engineering |
| Data leakage from uploaded MRI files | Volumetric DoS on public demo |
| SSRF via file upload | Issues requiring physical access |
We follow coordinated disclosure: please allow 90 days for a fix before public disclosure. We will credit researchers who report valid vulnerabilities.