corvid is an embedded, in-process database: it runs inside your application, opens no network ports, and talks to no services. The attack surface that matters is the data path — documents, queries, and the files it reads and writes.
Report vulnerabilities privately to the org owners via
GitHub's private vulnerability reporting on the affected repo
(Report a vulnerability → Security tab), or email the maintainer
listed on the org profile. Please include a minimal reproducer and the
engine/.binding version (corvid_ffi_version() where available).
We aim to respond within a few days. Fixes ride the normal release pipeline (a coordinated engine tag + binding bumps); pre-1.0, security fixes may land without an advisory when the affected surface has no consumers yet — we'll say so when you report.
- Untrusted document contents (deeply nested values, huge vectors, hostile strings) are in scope for every component; the value codec has explicit depth caps and the FFI layer copies borrowed views inside the call that observed them.
- The engine is
#![forbid(unsafe_code)]; the unsafe surface is the C ABI (corvid-ffi), sanitized in CI (ASan/UBSan/LSan over the C smoke suite) — reports againstcorvid.hconsumers welcome. - The MCP sidecar (
corvid-mcp) deliberately exposes a store to a local tool; treat its input as trusted-local, as documented.