| Version | Supported |
|---|---|
| 5.0.x | ✅ |
| 4.8.x | ✅ |
| 4.7.x | ✅ |
| 4.6.x | ✅ |
| 4.5.x | ✅ (≥ 4.5.2 for analyze_* sandbox) |
| below 4.5.2 | ❌ — upgrade for analyze_* path sandbox (GHSA-3q7p-736f-x44v) |
Security fixes land on the latest patch release. Prefer @stabgan/openrouter-mcp-multimodal@latest or pin 5.0.1.
Do not open public GitHub issues for exploitable security bugs.
- Email the maintainer via GitHub private vulnerability reporting (preferred), or contact the repo owner listed on npm.
- Include reproduction steps, affected version, and impact.
- Expect an initial response within 72 hours. We will coordinate disclosure and credit where appropriate.
| Control | Scope |
|---|---|
| Input path sandbox | Local paths on analyze_*, reference images, and async job reads must resolve inside OPENROUTER_INPUT_DIR (fallback: OPENROUTER_OUTPUT_DIR, then cwd). Violations return _meta.code: UNSAFE_PATH. |
| Output path sandbox | save_path on generate tools must stay inside OPENROUTER_OUTPUT_DIR. Symlink escapes blocked via realpath. |
| Legacy bypass | OPENROUTER_ALLOW_UNSAFE_PATHS=1 disables both sandboxes (discouraged). |
| SSRF protection | HTTP(S) fetches block private/reserved IPv4 and IPv6 ranges; outbound connections use IP pinning to mitigate DNS rebinding (since 4.8.0). |
| Async job isolation | get_chat_completion_status validates job_id format and resolves disk paths under OPENROUTER_OUTPUT_DIR/openrouter-jobs/ only (fixed in 4.7.0). |
| Credential redaction | API keys and Bearer tokens are redacted from logs and user-visible error messages. |
Configure sandboxes in .env.example:
OPENROUTER_INPUT_DIR=./inputs # readable local files
OPENROUTER_OUTPUT_DIR=./output # save_path writes + optional job persistence| ID | Severity | Fixed in | Summary |
|---|---|---|---|
| GHSA-3q7p-736f-x44v | Medium | 4.5.2 | analyze_image / analyze_audio / analyze_video read arbitrary local files without sandbox. |
Async job_id path traversal |
— | 4.7.0 | Malicious job_id could escape openrouter-jobs/ before disk read; blocked by isValidJobId + resolveSafeJobStatusPath. No public GHSA filed. |
| DNS rebinding SSRF | — | 4.8.0 | Connect-time DNS re-resolution could bypass pre-flight SSRF checks; mitigated by IP-pinned HTTP(S) fetches. No public GHSA filed. |
Post-mortem for the analyze-path issue: docs/solutions/security-issues/analyze-path-traversal-ghsa-3q7p-736f-x44v.md.