Report a vulnerability privately through GitHub's RED THREADS vulnerability report form. Private vulnerability reporting is enabled for this repository.
Include the affected version, component, impact, and a minimal fictional reproduction. Remove tokens, private case data, confidential sources, and identifying local paths. A report can demonstrate unsafe handling without disclosing a real investigation.
Relevant defects include executable interpretation of case text, unsafe source links, unintended file writes or overwrites, traversal through evidence references, and unintended network or data disclosure from bundled code.
The current release is v0.1.0. No response deadline or guaranteed support period is promised. Please allow the maintainer to assess a reported defect and coordinate an appropriate fix before publishing exploit details.
Host permissions, account access, and third-party source availability are outside the bundled toolkit. If a report crosses those boundaries, identify which operation belongs to RED THREADS and which belongs to the host.
An atlas embeds its case data. Hiding a node with a filter does not remove that record from the HTML. Review the full case before sharing a generated artifact. Read privacy and custody for the local-tool and host-processing boundaries.