If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue.
- Use GitHub's private vulnerability reporting to submit a report.
- Include steps to reproduce, impact assessment, and any suggested fix.
We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues.
| Version | Supported |
|---|---|
| Latest | Yes |
Cortex is a reference app for cross-session agent memory. Security concerns most relevant to this project include:
- Unintended exposure of session data or memory files
- Path traversal in config or skill loading
- Injection via crafted YAML messages