Skip to content
BreachPilot

Security

Found a vulnerability? Tell us privately first.

BreachPilot ships offensive security tooling, so a flaw in BreachPilot itself carries real risk. Report it through private channels — never as a public issue — and give maintainers time to fix it before disclosing.

How to report

1. Use private reporting

The repository publishes no dedicated security contact, so use GitHub private vulnerability reporting. Details stay visible only to maintainers until a fix is ready — do not open a public issue.

2. Include what matters

What you found, which version or commit, lab-only reproduction steps, and the impact boundary (operator box, target scope, or audit integrity).

Stay in scope while reporting

Reproduce in a lab you control only. Do not probe systems you don’t own — the same authorization rule as the tool itself: only test systems you own or have explicit written permission to assess.