Please report security vulnerabilities via GitHub Security Advisories rather than public issues.
- Acknowledge within 48 hours
- Patch within 7 days for critical vulnerabilities
- Coordinated disclosure after fix is released
Only the latest release receives security updates.
fleet-mem runs locally and does not make network requests except to a user-configured Ollama instance. Security concerns include:
- Path traversal via MCP tool inputs
- SQL injection in memory queries
- Symlink following during file indexing
- Shell injection in scripts