| Version | Supported |
|---|---|
| 2.0.x | ✅ |
| 1.0.x | ❌ |
If you discover a security vulnerability in aarambh-studio, please report it responsibly:
- DO NOT open a public GitHub issue for security vulnerabilities
- Use GitHub private vulnerability reporting or open a private GitHub Security Advisory for this repository
- If private reporting is unavailable, open a minimal public issue asking for maintainer security contact without exploit details
- Include a detailed description of the vulnerability
- Include steps to reproduce if possible
- We will acknowledge receipt within 48 hours
- We will provide a fix timeline within 7 days
Security concerns for aarambh-studio include:
- Model weight tampering or injection
- Checkpoint deserialization vulnerabilities
- Tokenizer exploits (adversarial inputs)
- Training data poisoning vectors
- Inference-time prompt injection
- Denial of service via crafted inputs
- Unsafe CUDA/SIMD or memory-mapped checkpoint boundary violations
- Inference server authentication, isolation, or streaming-safety bypasses
We follow a 90-day responsible disclosure policy. We ask that you give us reasonable time to address the vulnerability before public disclosure.