Per SECURITY.md ("GitHub private vulnerability reporting is not currently
enabled... open an issue without vulnerability details asking maintainers for
a private channel"), this issue contains no vulnerability details.
I have two verified security findings against mcode 0.4.12 (Linux, Node 26):
- a terminal-output handling issue in the TUI render path (this one is the
more serious of the two)
- an issue in how the agent's file tools interact with mcode's own
credential storage
Both have minimal reproductions and redacted evidence ready, neither involves
real credentials, and neither is currently discussed anywhere public.
Since the repo's private vulnerability reporting is not enabled and no
security email is listed, could you either enable Security → Advisories →
Report a vulnerability, or point me at an alternative private channel? Once
one exists I will submit the full write-ups there.
cc @hetaoBackend (release coordinator per docs/maintainers.md)
Per SECURITY.md ("GitHub private vulnerability reporting is not currently
enabled... open an issue without vulnerability details asking maintainers for
a private channel"), this issue contains no vulnerability details.
I have two verified security findings against mcode 0.4.12 (Linux, Node 26):
more serious of the two)
credential storage
Both have minimal reproductions and redacted evidence ready, neither involves
real credentials, and neither is currently discussed anywhere public.
Since the repo's private vulnerability reporting is not enabled and no
security email is listed, could you either enable Security → Advisories →
Report a vulnerability, or point me at an alternative private channel? Once
one exists I will submit the full write-ups there.
cc @hetaoBackend (release coordinator per docs/maintainers.md)