OpenChat is currently under active development. Security fixes are applied to the latest version on the main branch.
| Version | Supported |
|---|---|
main |
✅ |
| Older versions | ❌ |
Please do not report security vulnerabilities through public GitHub Issues, Discussions, or other public channels.
If you believe you have found a security vulnerability in OpenChat, please use GitHub's Private Vulnerability Reporting feature to submit your report privately.
This allows the vulnerability to be investigated and discussed without publicly exposing details before a fix is available.
Please provide as much of the following information as possible:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Expected and actual behavior
- Potential security impact
- Affected component or functionality
- Relevant logs, screenshots, or proof-of-concept code, when appropriate
You do not need to provide a complete exploit. A clear description and reproducible steps are sufficient to begin an investigation.
After receiving a report, the maintainer will:
- Review and reproduce the reported issue.
- Determine its security impact and affected versions.
- Ask for additional information if necessary.
- Develop and test a fix when the issue is confirmed.
- Release or deploy the fix.
- Publish a security advisory when appropriate.
There is currently no guaranteed response or resolution time, but reports will be reviewed as soon as reasonably possible.
Please allow reasonable time for the issue to be investigated and fixed before publicly disclosing vulnerability details.
Security vulnerabilities should not be intentionally exposed through public issues before a fix is available.
Security reports are especially welcome for issues affecting:
- End-to-end encryption
- Identity and peer authentication
- Message integrity and signatures
- Replay protection
- Group authorization
- WebRTC communication
- Local encrypted storage
- Authentication and session handling
- Input validation and XSS
- API and signaling security
Reports about ordinary bugs or feature requests should be submitted through the project's normal public issue tracker instead.