Verso listens to a microphone, holds an API key, stores transcripts in plaintext and injects text into other applications by driving the clipboard and the keyboard. That is a meaningful amount of trust, so security reports are taken seriously and answered.
Use GitHub's private vulnerability reporting on this repository: Security tab, then Report a vulnerability. That opens a channel only the maintainer can see, so a finding does not become public before there is a fix.
Please do not open a normal public issue for anything exploitable.
There is no bounty. This is a free project with no revenue behind it, so the only thing on offer is a fast reply, credit in the release notes if you want it, and the fix actually shipping.
- Anything that gets audio, a transcript, or an API key off the machine in a way PRIVACY.md does not describe.
- Anything that lets another local process read a key, or read transcripts it should not reach.
- The local chime-board HTTP server (
127.0.0.1, ephemeral port, token required): missing authorisation, a token leak, or path traversal. - The updater: anything that could make it fetch or run something other than a version string.
- Import paths (settings, dictionary CSV, snippets JSON) reached by a file a user was tricked into importing.
- Text injection landing in the wrong window in a way an attacker can steer.
- An attacker who already runs code as your Windows user. Verso stores
transcripts unencrypted and this is documented rather than accidental: the
alternatives are a password on every launch or a DPAPI key that any process
running as you can also read, which is encryption in name only. A local
process running as you can read
%APPDATA%\Versono matter what Verso does. - An administrator on the machine. The data directory grants SYSTEM and Administrators deliberately, because backup and antivirus need them and an admin can read the file regardless.
- The unsigned installer. SmartScreen warning about an unknown publisher is expected and stated in the README. A code-signing certificate costs money this project does not have. That is a funding problem, not a vulnerability.
- Anything requiring physical access to an unlocked machine.
- Findings from an automated scanner with no demonstrated impact.
Stated so you know what has been checked rather than as a claim of perfection.
- API keys live only in Windows Credential Manager, encrypted with DPAPI under your account. They are never written to a config file, never logged, never included in an exception message, and Settings reports only that a key exists: not the value, not a masked prefix, not its length.
- Logs record events, never dictated text. The one exception is documented: a few lines name the window you dictated into.
- Text written to the clipboard is marked to be excluded from Windows Clipboard History, so transcripts are not eligible for cloud clipboard sync.
- The data directory's inherited permissions are tightened once on first run to your account, SYSTEM and Administrators. It fails open and retries rather than recording a success it did not achieve.
- No
eval, noexec, nopickle, no shell invocation reached by user text. The only subprocess isicacls, called with an argument list and no user input.
The latest release only. This is a single-maintainer project and there is no capacity to backport.