Please report security vulnerabilities privately through GitHub's private vulnerability reporting (the "Report a vulnerability" button on the repository's Security tab). Do not open a public issue for security reports.
You can expect an initial response within a few days. Once a fix is ready we'll coordinate disclosure and credit you, if you'd like.
Clauster is actively developed; only the latest release receives security fixes.
Clauster spawns and manages claude bridges and agent sessions (the standard
and pty remote-control bridges, claude --bg background agents, and the hosted
claustrum channel) on the host it runs on — it is trusted, host-local
infrastructure, not a multi-tenant service. Key considerations:
- Loopback-only by default; binding to a network interface requires auth (password login or a trusted reverse proxy) — see the networking guide for the full loopback / non-loopback auth matrix.
- Starting a bridge, editing a project's
CLAUDE.md, or cloning a repository runs code from the target directory on the host. Treatprojects_rootas trusted. - The clone and ghost-environment-reaper features reach the network / first-party APIs with the host's own credentials; they are gated (SSRF guards, typed confirmations, opt-in flags) but act on the operator's behalf.
- Release artifacts (the GHCR image and the standalone binaries) are
Sigstore-signed; verify them before running — see the
installation guide for the
cosign/gh attestation verifyflow.
Reports that require already having shell/host access, or that amount to "the operator can manage their own host," are generally out of scope.
The threat model above is backed by controls you can inspect in
.github/workflows/:
- Static + dependency analysis on every PR — CodeQL, OSV-Scanner, and GitHub dependency review; secret scanning and Trivy image scanning run in the security workflow.
- Continuous fuzzing — ClusterFuzzLite runs the Atheris harnesses in
fuzz/on PRs and on a schedule. - Pinned everything — every GitHub Action is pinned to a full commit SHA
(enforced transitively into reusable workflows), and Python dependencies
resolve from the committed
uv.lock. - Keyless, token-free releases — PyPI publishes via Trusted Publishing
(OIDC; no long-lived API token exists to steal), and every binary and
container image is Sigstore-signed with SLSA provenance — the
installation guide
documents the
cosign/gh attestation verifyflow. - Public scorecards — OpenSSF Scorecard and Best Practices are tracked continuously (badges in the README's Project health section).
- GHSA-h4g2-xfmw-q2c9
(2026-06) — non-loopback deployments could serve the dashboard
unauthenticated when
auth.enabledwas unset. Fixed fail-closed in 0.2.2; a non-loopback bind now refuses to start without enforced auth.