We support the latest published version of Mux Code (@agentmuxai/muxcode).
Older versions may receive security fixes at our discretion.
Do not open public GitHub issues for security vulnerabilities.
Email: security@agentmux.ai
Please include:
- A description of the issue and its potential impact
- Steps to reproduce (proof-of-concept welcome)
- The version affected (
muxcode --version) - Your operating system and Node.js version
- Any suggested remediation
- Acknowledgement: within 3 business days
- Initial assessment: within 10 business days
- Coordinated disclosure: we follow a coordinated disclosure model. Please give us reasonable time to investigate and ship a fix before public disclosure.
In scope:
- The
muxcodeCLI and the@agentmuxai/muxcodenpm package - How it runs tools: shell commands, file edits, MCP servers it starts
- How it downloads and runs models and
llama-server - The build and publish workflows in this repository
Out of scope:
- Vulnerabilities in upstream dependencies or in model providers' APIs — please report to those projects; we will pick up the fix on the next release.
- The AgentMux desktop app — report through agentmuxai/agentmux.
- Issues requiring physical access to an unlocked machine
We will credit reporters in release notes (with permission) for valid findings.
This policy does not create any warranty obligation. Mux Code is provided "AS IS" — see LICENSE.