Only the latest published release (and main) receives security
fixes. wavecode is a local CLI tool; there is no server component
and no backport cadence to older tags.
Use GitHub's private security advisories for daftpunkwav/wave-code. Please do not open a public issue for anything exploit-looking.
Include: the affected command surface (exec / serve / acp /
REPL), a reproduction (repo layout, config, invocation), and your
assessment of impact. You will get an acknowledgement within a few
days and a fix timeline once the report is triaged.
In scope:
- Sandbox escapes: reads/writes/exec outside the workspace that the permission modes promise to confine, including Windows path semantics (backslashes, drive prefixes, junctions) and symlinks.
- Approval bypasses: paths where a tool runs without the prompted consent, or a deny/allow decision is misapplied.
- Credential handling: API keys or tokens leaking into session journals, exports, logs, error messages, or telemetry (there is no telemetry).
- Network surfaces: the local app server (auth, origin checks), MCP client/server transport, and SSRF in web fetch/search.
- Terminal integrity: untrusted text reaching the terminal as control sequences (escape injection, OSC abuse).
- Supply chain: the install/update path (asset verification, self-update swap).
Out of scope:
- Prompt injection making the model produce bad code within its granted permissions (an inherent LLM property; the sandbox is the boundary).
- Attacks requiring local malware already running as the user.
- Volumes/rate issues against external services.
- The path sandbox is deny-first with rules persisted per grant;
wavecode doctorreports the effective confinement. - Release archives and the self-update path verify sha256 checksums before install; a failed verification aborts without touching the running binary. The checksum ships with the same release (no out-of-band signature chain) — the HTTPS github.com origin allowlist plus the checksum are the accepted trust root for self-update.
- Untrusted text is sanitized through one shared terminal gate before rendering; notifications ride tmux-safe wrappers.
- Provider credentials resolve from the
env_keyenvironment variable first; an inlineapi_keyin config.toml is an accepted plaintext convenience —doctorreports the key source and flags inline storage, and the shell/script tools strip credential-shaped names from child-process environments. - Private files (journals, grants, spill store) are written mode 0600 on Unix; on Windows no extra ACL is applied because files under the user profile inherit owner-scoped default ACLs (accepted).
wavecode mcp serveexposes the full local tool registry to its stdio client with no approval gate: the local MCP client is the operator-configured, same-user process that spawned the server and is trusted (MCP places tool-approval responsibility on the client). Providerenv_keynames are still stripped from tool child environments on this surface; the sessionwavedenylist is not consulted there (it is session-policy, not a serve-surface control).