Thanks for taking the time to look at paige's security surface.
Please do not open a public issue for a vulnerability.
Email the maintainer privately at the address linked from the project's GitHub profile, or open a private security advisory on the repository (GitHub → Security → Report a vulnerability).
What to include:
- A description of the issue and the steps to reproduce.
- The paige version (
./scripts/prod.sh statusshows the wheel). - Whether the issue is exploitable today, or only under specific configuration.
What to expect:
- Acknowledgement within a few business days.
- A fix or mitigation timeline once the issue is confirmed.
- Credit in the release notes if you'd like (let us know in your report).
paige's threat surface is small but non-trivial:
- IM credentials —
PAIGE_FEISHU_APP_ID/PAIGE_FEISHU_APP_SECRETlive in~/.paige/.envand grant outbound message + card access. The repo'sprod.shstrips outbound-proxy env vars before launch. - tmux pane control — paige sends keystrokes into the bound
pane. A vulnerability that lets an unauthorised user trigger
send_keysis effectively remote code execution on the host (whateverclaudewill run). - Access control —
PAIGE_ALLOWED_USERS/PAIGE_ADMIN_USERSgate who can interact with the bot. Default is open to anyone the bot can hear from; setting a real allow-list is strongly recommended on any shared deploy.
- Findings against the IM backend itself (Lark / Feishu) — please report those to the backend vendor.
- Findings against
claude(the agent paige bridges to) — please report those to Anthropic. - Issues that require root or local-shell access on the host paige runs on (already game-over by other means).
paige is pre-1.0 and ships from main. Security fixes target the
latest released wheel; no long-term support branches yet.