Maintainers and community take security bugs seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.
To report a security issue, please use the GitHub Security Advisory "Report a Vulnerability" tab.
Please do not report security vulnerabilities through public GitHub issues, discussions, or Discord.
Important
Automated AI-generated reports without human review are not allowed and will be rejected. This is an open-source project maintained by volunteers. We do not have the resources to review reports that could have been avoided with proper human oversight.
While we have no issue with reporters using AI tools as an aid, it is your responsibility as a reporter to ensure that all reports are carefully reviewed and meet our quality standards. Contributors who repeatedly submit unreviewed, low-effort AI output may be banned.
We expect AI-assisted work, not AI-driven work. Use AI as a tool, not as a stand-in for your own review. It does not matter who submits it. Whether it's an agent acting on its own or a human relaying its output unread. What matters is whether you reviewed, verified, and understood your report or response before you sent it.
If you are using any kind of AI assistance for a security report or response, it must be disclosed in your report.
If you are using any kind of AI assistance for a security report or response, this must be disclosed, along with the extent to which AI assistance was used (e.g. used to help investigate the issue vs. used to write the report itself).
Security advisory responses must be written in your own words, same as described below for the meat proxy problem. The one exception is AI-assisted translation, if you use AI to translate a response into English, disclose that here too. As a small exception, trivial tab-completion doesn't need to be disclosed, so long as it is limited to single keywords or short phrases.
Disclosure does not exempt a report or response from this policy. If a security report or advisory response was primarily generated by an AI tool with little more than a copy and paste on your end, that is still AI-driven, whether or not you disclosed it.
A more detailed disclosure that meets our bar:
I consulted ChatGPT to understand the codebase but the solution was fully authored manually by myself.
A disclosure like the one below is honest, but the response will still be treated as AI-driven:
This security advisory was written primarily by Claude Code.
Failure to disclose this is first and foremost rude to the human operators on the other end of the report, but it also makes it difficult to determine how much scrutiny to apply to the submission.
Don't be a meat proxy between an AI and the security team either (the term is borrowed from this post). If we ask a follow-up question about your report and you relay it to an AI, then paste back an answer you haven't read or checked against the actual code, you haven't added anything, we could have asked the AI ourselves. We are volunteers handling this on our own time. Read the response, verify it, and write your own answer.
In a perfect world, AI assistance would produce equal or higher quality work than any human. That isn't the world we live in today, and in most cases it's generating slop. I say this despite being a fan of and using them successfully myself (with heavy supervision)!
When using AI assistance, we expect reporters to understand the findings they're submitting and be able to answer critical questions about them. It isn't a maintainer's job to review a report so broken that it requires significant rework to be acceptable.
Please be respectful to maintainers and disclose AI assistance.
To help us better understand and resolve the issue, please include as much of the following information as possible:
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue
We will send a response indicating the next steps in handling your report. After the initial reply to your report, the security team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
- Security issues will be disclosed in a coordinated manner
- We will credit reporters in the security advisory unless anonymity is requested
- We request that you do not publicly disclose the issue until we have released a fix
If you discover a security vulnerability in a third-party dependency used by Seerr, please report it directly to the maintainers of that module. You can also notify us through our security advisory process so we can:
- Track the issue and monitor for updates
- Apply patches or workarounds if available
- Coordinate with upstream maintainers when necessary
- Communicate the impact to our users
We regularly monitor and update our dependencies to address known security vulnerabilities.
Security updates and advisories will be published on our GitHub Security Advisories page.
For general questions and support (non-security related):