We take security seriously ! If you find a vulnerability, please report it privately so we can fix it before it affects users.
-
Include:
- Description of the issue
- Steps to reproduce
- GitBook version or environment details
- Possible impact
We aim to acknowledge all reports within 96 hours.
- v0.3.x – current stable version (receives all updates)
- v0.2.x – legacy support (critical fixes only)
Older versions may not receive fixes. Upgrade to the latest version for security.
- Always use the latest release.
- Be careful when crawling untrusted GitBooks.
- Consider running the CLI in an isolated environment.
- Verify downloaded content before using it in automated pipelines.
- Confirm and assess the vulnerability.
- Fix privately.
- Release a patched version and update the changelog.
- Notify users via GitHub releases.
For non-security issues (bugs, features, documentation), please use GitHub Issues.