Security updates are provided for the latest main branch and the most recent published releases. Please upgrade when possible.
Please do not open a public GitHub issue for security vulnerabilities.
If you believe you have found a security vulnerability in PrivateGPT, report it privately so maintainers can investigate and remediate before public disclosure.
- GitHub Private Vulnerability Reporting (when enabled on this repository): use the Security tab → Report a vulnerability.
- Discord: join the PrivateGPT Discord and ask a maintainer for a private channel — do not paste exploit details in public channels.
- X / social: @ZylonPrivateGPT can be used only to request a private contact path, not to share technical details.
Please include:
- A description of the issue and its impact
- Steps to reproduce (or a proof of concept)
- Affected component(s), versions, and environment details
- Any suggested remediation if known
- We will acknowledge receipt as soon as possible.
- We will keep you informed of investigation and remediation progress.
- Please allow a reasonable window to fix and release a patch before public disclosure.
Thank you for helping keep PrivateGPT and its users safe.