| Version | Supported |
|---|---|
| 1.3.x | ✅ Active support |
| < 1.3 | ❌ No longer supported |
Please do NOT report security vulnerabilities via public GitHub Issues.
Instead, report vulnerabilities using one of the following private channels:
- Go to the repository on GitHub
- Click Security → Advisories → Report a vulnerability
- Fill in the form with as much detail as possible
Send a detailed report to: rajdeep@smokemonkey.dev
Use the subject line: [SECURITY] Smoke Monkey Canvas — <brief description>
A good vulnerability report includes:
- Description — What is the vulnerability? What component is affected?
- Impact — What can an attacker do? What data or systems are at risk?
- Steps to Reproduce — Minimal steps or proof-of-concept code
- Environment — OS, Node.js version, Canvas version
- Suggested Fix — (Optional) If you have a proposed remediation
| Stage | Timeline |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial assessment | Within 7 days |
| Fix timeline communicated | Within 14 days |
| Patch released | Varies by severity |
We follow responsible disclosure: once a fix is shipped, we will publish a security advisory crediting the reporter (unless you prefer to remain anonymous).
Smoke Monkey Canvas is designed to run locally (on localhost). If you expose it on a network or public internet, be aware:
- No built-in authentication — The API has no auth by default. Do not expose port 3333 to the public internet without adding an authentication layer (reverse proxy + auth middleware).
- Agents have filesystem access — Each agent has a working directory and can read/write files. Scope working directories carefully.
- MCP servers run as subprocesses — MCP servers are spawned as child processes with the same OS permissions as the Node.js server process. Only attach MCP servers you trust.
- API keys stored in SQLite — Keys are stored at
~/.smoke-monkey/canvas.db. Protect this file with appropriate filesystem permissions. - WebSocket — The WebSocket endpoint (
/ws) has no auth. Secure it if deploying on a network.
The following are not considered security vulnerabilities for this project:
- Vulnerabilities requiring physical access to the machine
- Social engineering attacks
- Denial-of-service attacks against a single-user local deployment
- Issues in third-party dependencies (report those upstream)
Thank you for helping keep Smoke Monkey Canvas secure! 🔒