| Version | Supported |
|---|---|
| latest | ✅ |
ShareGo takes security seriously. If you discover a security vulnerability, please report it responsibly.
Do NOT open a public issue for security vulnerabilities.
- Email: Send a detailed report to the repository owner via GitHub private vulnerability reporting
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment within 48 hours
- Status update within 7 days
- We aim to release a fix within 30 days for confirmed vulnerabilities
The following are in scope for security reports:
- Cryptographic weaknesses in the key exchange or encryption
- Authentication or authorization bypass
- Data leakage (keys, plaintext, session data)
- Memory safety issues (key material not zeroed)
- Protocol-level attacks (replay, MITM, downgrade)
- Transport layer vulnerabilities
- Denial of service on local network (inherent to local-network design)
- Physical access attacks
- Social engineering
- Issues in third-party dependencies (report upstream, but let us know)
ShareGo is designed with security as a primary goal:
- No cloud servers — all communication stays on local network
- End-to-end encryption — XChaCha20-Poly1305 (AEAD) via the
cryptographypackage - Ephemeral keys — fresh X25519 key pairs generated per session, never persisted
- Memory wiping — derived session keys are overwritten when the session ends. See the threat model for the limit on the X25519 private key.
- No data persistence — nothing is written to disk
For full details, see docs/THREAT_MODEL.md.