Please do not report security vulnerabilities through public issues.
Instead, use GitHub's private vulnerability reporting on the affected repository (the Security tab → Report a vulnerability), or reach the maintainers privately via Discord.
Include, where you can:
- The repository and version affected
- A description of the vulnerability and its impact
- Steps to reproduce
- Any suggested remediation
We aim to acknowledge reports promptly and will keep you informed as we work on a fix.
lemonfiber's threat model is documented in full in the spec (40-quality/security.md). The single highest-severity class is VPN egress leakage — a misconfiguration exposing a user's home IP to torrent peers. The stack verifies this empirically at runtime, but reports of ways it can be defeated are especially valuable.
In scope: the lemonfiber binary, the stack definitions, credential handling, the
VPN isolation path, and the web UI.
Out of scope (stated in the threat model, not defended): nation-state adversaries, physical access to the host, a compromised host operating system, and a malicious operator on their own machine.
Security fixes may be merged ahead of their spec change under the maintainer override, precisely because a public spec PR describing a vulnerability must not precede its patch. The spec is corrected immediately after.