If you find a security vulnerability in Oracle LoreKeeper, do not open a public issue.
Instead, send a private report via:
- GitHub Security Advisories — navigate to
https://github.com/ForgedEmir/RAG/security/advisoriesand create a new advisory. - Direct message — contact the maintainer via GitHub at @ForgedEmir.
You should receive a response within 48 hours. If you don't, follow up.
- Description of the vulnerability
- Steps to reproduce (PoC preferred)
- Potential impact
- Suggested fix (optional)
- API endpoints and authentication
- PII masking and data leakage
- Prompt injection via the RAG pipeline
- Dependency vulnerabilities with known CVEs
- Theoretical attacks requiring local machine access
- Rate limiting bypasses without demonstrated impact
- Issues in dependencies that are already patched in newer versions
We believe in coordinated disclosure. Please give us reasonable time to fix the issue before publishing it publicly.