Only the latest published version of @sealdrop/cli receives security fixes.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting to send a confidential report.
Include the affected command and version, reproduction steps, expected impact, and any suggested mitigation. Do not include real encryption keys, URL fragments, private links, plaintext filenames, or files belonging to another person.
We will acknowledge a complete report as soon as practical and coordinate a fix and disclosure when the issue is confirmed. SealDrop does not currently operate a paid bug bounty program.