GroktoCrawl is a self-hosted open source project. We take security vulnerabilities seriously and appreciate responsible disclosure.
If you discover a security vulnerability, please report it privately by emailing magnus@groktop.us.
Please do not open public GitHub issues for security vulnerabilities.
- A clear description of the vulnerability
- The affected component and version
- Steps to reproduce (proof of concept)
- Any suggested mitigation (optional but appreciated)
- Acknowledgement: Within 48 hours
- Initial assessment: Within 5 business days
- Fix timeline: Depends on severity — critical issues are typically resolved within a week
Set API_KEY in your .env file to enable bearer token authentication.
All API endpoints (except /health) require Authorization: Bearer ***or X-API-Key: ` headers.
When no API_KEY is configured, every response includes an
X-Security-Warning header and a structured warning in the /health
endpoint body. The CLI prints a one-time warning on first use.
See the README for setup instructions.
The browser service and scraper service block navigation to:
- RFC 1918 private IP ranges (10.x, 172.16-31.x, 192.168.x)
- Loopback (127.x, ::1)
- Link-local (169.254.x)
- Cloud metadata endpoints (169.254.169.254)
- Docker host (*.docker.internal)
This prevents SSRF-based pivoting through the headless browser.
Internal services (browser-svc, scraper-svc, parse-svc) no longer publish ports to the host. They are only reachable through the agent API on port 8080 via Docker's internal DNS.
Pull requests from forks run workflows from the PR merge ref, so in-repo
guards (fork conditions, detection steps) are defense in depth only — a
workflow edit can strip them. The authoritative control is platform-level
(org runner-group restriction and workflow-run approval). See
docs/runbooks/self-hosted-runner-fork-protection.md
for the shipped in-repo controls (#562), the exact org-level remediation
steps (allows_public_repositories=false, optional
restricted_to_workflows + allowlist, "Require approval for all external
contributors"), and the residual risk while those org-level settings are
deferred.
| Version | Supported |
|---|---|
| 0.5.x | ✅ |
| < 0.5 | ❌ (no auth/security features) |
We thank the following individuals for their responsible disclosures:
- Bertie — Reported the unauthenticated browser pivot and private network SSRF vector that led to the v0.5.0 security release.