If you discover a security vulnerability in UNWIND, please report it responsibly.
Email: security@brugai.com Alternative: Open a private security advisory on GitHub.
Please include:
- Description of the vulnerability
- Steps to reproduce
- Affected component (enforcement pipeline, CRAFT, sidecar, adapter, Ghost Mode)
- Impact assessment if known
- Acknowledge: within 48 hours
- Triage: within 7 days
- Fix: within 90 days (critical vulnerabilities prioritised)
In scope:
- Enforcement pipeline bypasses
- CRAFT chain integrity issues
- Sidecar authentication or authorization flaws
- Ghost Mode escape or data leakage
- Adapter input validation issues
- Path jail or self-protection bypasses
Out of scope:
- Social engineering or phishing
- Denial of service against a self-hosted Pi
- Issues in upstream dependencies (report to those projects directly)
- Attacks requiring physical access to the host
If you run UNWIND with OpenClaw, review these settings for defence-in-depth:
session.dmScope: Set toper-channel-peer(not the defaultmain). The default shares a single session across all DM senders, which undermines UNWIND's per-session taint tracking. Withper-channel-peer, each sender gets an isolated session.gateway.auth.mode: Ensure a token or password is set. If the gateway binds to a non-loopback address without authentication, tool calls can bypass the UNWIND adapter entirely.tools.fs.workspaceOnly: Set totrueto complement UNWIND's path jail at the OpenClaw level.tools.elevated.enabled: Leave asfalseunless you have a specific need. UNWIND blocks elevated exec on tainted sessions, but defence-in-depth is better.
Valid reporters will be credited in this file's Hall of Fame section (unless they prefer anonymity).
No reports yet — be the first!