Please do not open a public issue for vulnerabilities that could expose authenticated browser content, execute commands in an unintended tab, bypass a claim boundary, or allow another local process to impersonate the extension.
Use GitHub private vulnerability reporting when available. Include:
- affected version and browser;
- reproduction steps;
- expected and actual behavior;
- whether authenticated page data or write actions are involved.
- The bridge binds to
127.0.0.1only. - Protocol V2 extension traffic uses a per-extension bearer token.
- Browser CORS responses are restricted to extension origins.
- Structured actions default to the isolated execution world.
- Users can pause command execution globally from the extension popup.
- Trusted-site mode rejects tab commands outside the locally stored hostname list.
- Arbitrary JavaScript execution is an advanced compatibility feature and should be treated as privileged.
Security fixes are applied to the latest development version until the first stable release is published.