Security fixes are applied to the latest CursorBloom release. Version 1.2.x is currently supported.
Please use GitHub private vulnerability reporting instead of opening a public issue for a suspected security or privacy problem.
Include the affected version, Windows version, reproduction steps, expected impact, and any relevant crash or diagnostic details. Remove credentials, private paths, unrelated process information, and personal data before attaching logs or screenshots.
CursorBloom is a small volunteer project and does not currently operate a paid bug-bounty program. A report will be acknowledged and triaged as promptly as practical.
For ordinary defects, rendering problems, or compatibility requests that do not disclose a security weakness, use the repository issue tracker.