Report security vulnerabilities in the GrowthBook CLI by emailing the GrowthBook security team at security@growthbook.io.
Do not file a public GitHub issue for a security vulnerability. Reporting privately gives us time to patch before details are public, which protects current users.
We appreciate responsible disclosure and will make every effort to acknowledge your contribution.
The full policy — including how we patch, release, and disclose — is documented in the main GrowthBook repository: https://github.com/growthbook/growthbook/blob/main/SECURITY.md.
For vulnerabilities in the GrowthBook app, Cloud, or SDKs rather than this CLI, use the same address; the policy above covers all GrowthBook open source projects.