Skip to content

Security: lanthissa/tmux-nvim-link

Security

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest tagged release.

Reporting a vulnerability

Please report vulnerabilities privately through GitHub Security Advisories once the repository is published. Until then, contact the maintainer privately rather than opening a public issue. Include reproduction steps but never include a real signing token or signed URL.

Security boundaries

Links are authenticated local requests, not a remote-access protocol. The handler requires an HMAC-SHA256 signature from a token containing at least 32 random bytes, then validates the existing file, cwd, multiplexer, pane, and socket. Normal click accepts only signed custom schemes; Option-click is an explicit trust action for an unsigned file:// URL or plain path. Anyone who can read the token can create valid links with the user's authority. Tokens must be canonical Base64 for at least 32 bytes. Keep the token mode 0600, do not sync it, and rotate it by uninstalling with --purge then reinstalling. The scheme does not sandbox Neovim or multiplexer processes.

There aren't any published security advisories