Skip to content

Security: Vimalinx-zero/VibeMouse

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are made on the latest 0.2.x release line. Earlier releases may receive a best-effort workaround, but users should plan to upgrade.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability, leaked credential, or proof of concept that could compromise a user's desktop.

Send a private report to vimalinx@gmail.com with:

  • the VibeMouse version and installation method;
  • affected desktop/session details;
  • reproducible steps or a minimal proof of concept;
  • impact and any mitigation you have already applied.

Please redact dictated content, API keys, command-auth tokens, signed URLs, and unrelated personal information. The maintainer will acknowledge valid reports within 7 days, provide a status update within 21 days, and coordinate a fix and disclosure timeline with the reporter where practical.

In scope

Reports are especially useful for weaknesses involving:

  • the loopback settings or command server;
  • configuration, API-key, command-token, log, or status-file disclosure;
  • microphone/audio handling and cloud-ASR request handling;
  • text injection, clipboard use, input-device access, and generated services.

Third-party models, cloud services, desktop environments, and operating-system bugs are outside this repository's direct control. Please report issues in VibeMouse's integration or documentation here, and report service-specific vulnerabilities to the relevant provider as well.

Safe testing

Only test against machines, accounts, recordings, and cloud credentials that you own or are explicitly authorized to use. Do not publish real recordings, transcripts, credentials, or exploit details before a coordinated fix exists.

There aren't any published security advisories