Only the latest Claudex release receives security fixes.
Do not open a public issue when a report contains credentials, OAuth artifacts, source code, or a working exploit. Use the repository's private vulnerability reporting form.
Include the Claudex version, operating system and architecture, a redacted reproduction, and the expected security boundary. Never attach ChatGPT, Codex, Claude, or CLIProxyAPI credentials.
Claudex downloads and runs a pinned third-party CLIProxyAPI binary. Reports about Claudex's installer, checksum validation, local binding, secret handling, process ownership, update, rollback, or uninstall logic belong here. Upstream CLIProxyAPI vulnerabilities should also be reported to its maintainers.