Mnemo is a local-first study application, so security and user trust matter.
Please do not publicly disclose security vulnerabilities before giving the maintainers a reasonable chance to respond.
To report a vulnerability, contact the project maintainer:
- Submit a private vulnerability report, or
- email security@mnemo.one.
Do not include a vulnerability in a public issue or discussion. General support requests belong in SUPPORT.md.
Please include:
- a clear description of the issue
- steps to reproduce
- affected versions or commits if known
- potential impact
- suggested fix if you have one
Security issues may include, but are not limited to:
- unsafe file handling
- arbitrary code execution
- insecure update behavior
- data loss or data exposure
- unsafe AI/model loading behavior
- unsafe plugin, theme, or extension behavior
- local privacy issues
Mnemo is maintained as a passion project. Response times may vary, but responsible reports are appreciated.