Project: connectors (ellmos-connectors)
Ecosystem: ellmos-ai
Umbrella: open-bricks
Last Updated: 2026-09-14
| Version | Supported / Unterstützt | Status |
|---|---|---|
1.2.x |
✅ Yes | Current Active Release Line |
1.1.x |
✅ Yes | Maintenance Release Line |
< 1.1.0 |
❌ No | End of Life / Upgrade Recommended |
If you discover a security vulnerability in this project, please do not open a public GitHub issue.
- GitHub Security Advisory (Recommended / Empfohlen): Open a private advisory via GitHub Security Advisories.
- Direct Maintainer Contact:
Reach out via dedicated security contact emails:
security@open-bricks.org,security@ellmos.ai,lukas@open-bricks.org, or maintainer emailsupport@lukasgeiger.com.
Please include as much detail as possible:
- Type of vulnerability (e.g., credential exposure, SSRF, command injection, path traversal)
- Affected connector module (
telegram_connector.py,discord_connector.py,signal_connector.py,slack_connector.py,imessage_connector.py, etc.) - Step-by-step reproduction instructions and minimal proof-of-concept
- Potential impact and threat model
- Suggested mitigation or patch (if available)
- Acknowledgment: Within 48 hours (Empfangsbestätigung innerhalb von 48 Stunden)
- Initial Assessment & Triage: Within 5 business days (Ersteinschätzung innerhalb von 5 Werktagen)
- Fix & Advisory Release: Coordinated disclosure following verified resolution
- Zero Runtime Secret Persistence:
connectorsnever writes API tokens, bot credentials, or session data to disk or persistent state stores. - Repr & Log Leak Prevention:
ConnectorConfig.auth_configis defined withfield(repr=False). All connector classes ensure their__repr__()implementations mask secrets and only expose identifier and status metadata. - Pluggable Secret Resolution:
Secrets can be resolved via environment variables (
os.environ),.envfiles, or through the decoupledSecretAdapterinterface for external key vaults. - Injection Safety:
Process invocations in
SignalConnectorandiMessageConnectorstrictly pass arguments as structured arrays tosubprocess.run(withoutshell=True) to prevent shell injection. - Zero Mandatory Runtime Dependencies:
The core library relies exclusively on Python standard library modules (
urllib,json,threading,subprocess,sqlite3, etc.), minimizing supply-chain attack surfaces. - Local Platform & SQLite Isolation:
iMessageConnectorqueries local macOSchat.dbin read-only mode using strict parameterized queries, never modifies database records, and immediately fails closed with safe status on non-Darwin platforms. - Encrypted Transport:
All HTTP-based connectors (
SlackConnector,TelegramConnector,DiscordConnector,WhatsAppConnector,WebhookConnector,HomeAssistantConnector) enforce TLS/HTTPS endpoints.
- Third-party platform infrastructure outages or security incidents (Slack, Telegram, Discord, Meta WhatsApp, Signal Network, Home Assistant).
- Vulnerabilities within external system binaries such as
signal-cli(report upstream to AsamK/signal-cli). - Insecure storage of secrets in user code, configuration files, or environment variable management outside this library's boundaries.