Security research
Security Policy
Report vulnerabilities privately, understand what testing is in scope, and read the authorization before you begin.
Reporting a vulnerability
Do not open a public GitHub issue for a security vulnerability.
Email: security@tokenburner.net
Include: clear description, reproduction steps, affected versions if known, your name (or pseudonym) and disclosure preferences. We acknowledge within 3 business days.
Disclosure process
- We confirm privately and assess severity.
- We develop and test a fix.
- We coordinate a disclosure date with the reporter.
- We release a patched version with a security advisory.
- We credit the reporter (unless they prefer anonymity).
Targets: critical (RCE, sandbox escape, credential exfiltration) within 7 days; high within 30 days; lower in regular releases.
Bug bounty: Not currently. We do not offer payment for reports.
What you may test
In scope: tokenburner.net and its subdomains; our checkout, licence-delivery and update endpoints; and the Tokenburner application running on a machine you own or control.
- PTY input/output leaking to unintended processes.
- Screenshot bytes accessible outside the app's data directory without consent.
- Bypasses of the Tauri capability allowlist.
- Tampering with auto-update.
- Code injection via crafted PTY input/output.
- Privilege escalation through the spawn mechanism.
- MCP server bypasses — unauthorized cross-pane access, secret leakage, loopback bypass.
Out of scope: any account or data that is not yours; denial-of-service and volumetric load testing; and physical or social-engineering attacks against us, our suppliers, or our people.
- Vulnerabilities in third-party CLIs run inside Tokenburner panes.
- Operating system vulnerabilities.
- Social engineering of users.
A note on our providers: our site, checkout, storage and release hosting run on Stripe, Cloudflare, Resend and GitHub, so testing us necessarily touches infrastructure they operate. What is out of scope is testing their platforms as such — go to their own programmes for that. Testing our configuration of them, at our endpoints, is in scope.
Disclosure timing is your decision
About disclosure timing — a request, not a condition.
We would be grateful for 90 days before you publish, and we will work with you to fix things faster than that. But it is not a condition of this authorisation and it is not a condition of your licence. If you publish sooner, you do not lose the authorisation above, and we will not treat your publication as a breach of any agreement between us, as a ground for suspending or terminating your licence, or as triggering any indemnity you owe us.
Nothing in this Policy restricts your right to publish an assessment of Tokenburner's security. A coordinated-disclosure window that is enforced by withdrawing your protection is a restriction on a performance assessment dressed as a courtesy, and we are not going to write one. This authorisation is ours alone to give and covers only claims we could bring.