Security fixes are made on the current main branch and released in the next
appropriate version.
Please use GitHub's private vulnerability-reporting flow for this repository:
https://github.com/hishamkaram/claude-code-router/security/advisories/new
Do not open a public issue for a suspected vulnerability. Include a clear impact description, reproduction steps, affected version or commit, and any suggested mitigation. Never include API keys, OAuth tokens, local session tokens, or other credentials in the report.
You can expect an acknowledgement within seven days. We will coordinate a fix, release, and disclosure timeline with the reporter where appropriate.