Please do not disclose vulnerabilities in a public issue.
Report suspected security problems privately to security@openinterpreter.com. Include the affected version, impact, reproduction steps, and any suggested mitigation. Do not include real user data or active credentials.
Only the latest released version and the current main branch are expected to receive security fixes. This policy may be expanded as the public release process matures.