Report suspected vulnerabilities privately through GitHub private vulnerability reporting. If you cannot use GitHub, email operatornest+security@gmail.com. Include the affected package version or revision, the operation involved, a minimal reproduction and the impact you see.
Do not publish exploit details in an issue or pull request before maintainers have assessed the report. Maintainers will coordinate a response and any disclosure with the reporter.
@operatornest/convex-models-dev downloads a public catalog from https://models.dev/api.json (with https://models.opencode.ai/api.json as a fallback) and stores it in component tables. It has no API keys, no tokens, no webhooks and no environment variables, and it stores no personal data. Its only outbound request is a GET of the configured source URL.
These are the areas worth a report:
- A hostile or broken upstream catalog. The payload is untrusted. The sync validates every row, skips malformed models without deleting stored rows, aborts when the payload is smaller than
minProvidersorminModels, and skips a removal pass that would delete more than 20% of rows unless a caller passesforce. Reports of a payload that gets past these guards, exhausts memory or time in the sync action, or corrupts stored rows are in scope. - The source URL.
config.updateaccepts onlyhttpsURLs without embedded credentials. A way to point the sync at a non-https, credentialed or otherwise unintended target is in scope. - Caller authorization. The component does not authenticate callers.
config.updateandsync.noware public component functions, and the host app must guard the functions that call them. A report that depends on an app leaving them open is not a component vulnerability, but unclear documentation about it is a bug. - Stored error text.
syncState.lastErrorholds the host and HTTP status of a failure, never headers or bodies. A leak of other data there is in scope.
Only the latest published version receives fixes.