CmdTab
macOS window switching
MenuClose
Security
CmdTab security disclosure
Use this page to report security issues privately and understand which systems, versions, and testing methods are currently in scope.
Last reviewed:
Current documented app: 1.0.0
How to report a vulnerability
Report suspected security issues privately to tohsh17@gmail.com.
Include the affected URL, app version or build, macOS version, feature, clear reproduction steps, impact, logs that do not expose other people's data, and a minimal proof of concept when one is needed to validate the issue.
Current scope
In scope: the cmdtab.net website and APIs, dashboard authentication, analytics ingestion, trial registration, checkout and webhook handling, license generation and delivery, the native CmdTab app, update and release packaging, and the public repository configuration.
Third-party platforms such as Vercel, Resend, GitHub, and the configured commerce provider are governed by their own disclosure programs unless the issue is caused by CmdTab's integration or configuration.
Safe testing boundaries
Do not access data that is not yours, publish an unpatched vulnerability, destroy or alter production data, send malware, conduct social engineering, or perform sustained denial-of-service testing.
Use the minimum traffic and data needed to demonstrate the issue. Stop testing and report immediately if you encounter personal, licensing, or payment information belonging to another user.
Response and remediation
Reports are reviewed for reproducibility, affected versions, user impact, and available mitigations. CmdTab may request clarification or a safer proof of concept before confirming the issue.
No guaranteed response time or public bug-bounty payment is promised today. Coordinated disclosure timing should be agreed before technical details are published.