Report suspected vulnerabilities in the OpenAI CLI privately by emailing disclosure@openai.com. Follow OpenAI's coordinated vulnerability disclosure policy.
Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
This policy covers the OpenAI CLI, source code in this repository, and official release artifacts. For security issues in other OpenAI products or services, use the same OpenAI disclosure process.
Please include:
- The affected package or product and version, release artifact, or commit.
- A clear description of the potential security impact.
- Sanitized steps to reproduce the issue or a minimal proof of concept.
- Relevant environment details, such as operating system, architecture, and installation method.
- Any known mitigations or workarounds.
Do not include live credentials, API keys, customer data, or unredacted sensitive logs. Remove access tokens, private keys, authorization headers, signed URLs, and sensitive request or response content before sharing supporting information.
Please give the maintainers a reasonable opportunity to investigate and address the issue before public disclosure. Thank you for helping keep the OpenAI CLI and its users secure.