Security fixes are published for the latest signed vX.Y.Z release of this LabVault customer SKU.
Report undisclosed vulnerabilities through GitHub private vulnerability reporting on this repository. Do not include lab addresses, passwords, or tokens in the report.
Do not file public issues for undisclosed vulnerabilities.
- No
docker.sock; ops vialabvault-opsdallowlist only - Startup
validate_external_configrejects demo secrets,ALLOWED_HOSTS=*, DEBUG /health/liveand/health/readyexpose no secrets or lab inventory- Staff-only LabVault CLI; no free-form device shell / host PTY
- Default compose DB password
labvaultis for lab installers only — change before shared use - Oneshot UI/API bootstrap is
admin/labvault!(LABVAULT_DEMO_DEFAULTS=1). A random file-only password is not the default unlessLABVAULT_BOOTSTRAP_RANDOM=1. Rotate on shared hosts.