Skip to content

Security: openai/openai-cli

SECURITY.md

Security Policy

Reporting a vulnerability

Report suspected vulnerabilities in the OpenAI CLI privately by emailing disclosure@openai.com. Follow OpenAI's coordinated vulnerability disclosure policy.

Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

This policy covers the OpenAI CLI, source code in this repository, and official release artifacts. For security issues in other OpenAI products or services, use the same OpenAI disclosure process.

What to include

Please include:

  • The affected package or product and version, release artifact, or commit.
  • A clear description of the potential security impact.
  • Sanitized steps to reproduce the issue or a minimal proof of concept.
  • Relevant environment details, such as operating system, architecture, and installation method.
  • Any known mitigations or workarounds.

Do not include live credentials, API keys, customer data, or unredacted sensitive logs. Remove access tokens, private keys, authorization headers, signed URLs, and sensitive request or response content before sharing supporting information.

Coordinated disclosure

Please give the maintainers a reasonable opportunity to investigate and address the issue before public disclosure. Thank you for helping keep the OpenAI CLI and its users secure.

There aren't any published security advisories