If you discover a security vulnerability in Octopus, please report it privately.
Do not open a public issue. Instead, send a description of the vulnerability to [INSERT EMAIL OR CONTACT METHOD].
Please include:
- Type of issue (e.g., SQL injection, XSS, privilege escalation)
- Affected component and version
- Steps to reproduce
- Potential impact
You should receive a response within 48 hours. If the issue is confirmed, a fix will be prepared and released as soon as possible, at which point the vulnerability will be publicly disclosed.
The following are considered in scope:
- The code-intelligence, octopus-review-agent, octopus-git, and octopus-code-reconstruct services
- The jvm-project-analyzer PSI plugin
- The octopus-frontend React application
- The octopus-infra shared libraries
- Third-party dependencies — report their vulnerabilities upstream
- Development-only configurations (e.g., default development passwords)
- Always change default passwords in production: MySQL, Neo4j, and the application encryption key.
- Set environment variables
MYSQL_PASSWORD,NEO4J_PASSWORD,GIT_PASSWORD, andOCTOPUS_ENCRYPTION_KEYinstead of using defaults. - Restrict network access to the internal microservice ports (8080-8083, 8377) in production.
- Use secret management for storing API keys (LLM providers, Git credentials).