Security fixes are applied on the latest main branch. Self-hosters should stay current with main (or tagged releases when published).
Please do not open a public GitHub issue for security problems.
Email the maintainers via the contact listed on the GitHub organization or open a private security advisory on the repository if available.
Include:
- Description and impact
- Steps to reproduce
- Affected commit / version if known
We will acknowledge receipt and work on a fix before any public disclosure.
- Set
NODE_ENV=productionorCAIRO_REQUIRE_WRITE_KEYS=true(disable bootstrap / open ingest) - Rotate write keys; never commit
.env/ secrets - Put TLS in front of Cairo and any relay
- Optionally set
CAIRO_WEBHOOK_SECRETand matchingHOOK_SECRETon relays - Restrict who can call MCP tools that mint keys or delete user data