Skip to content

Security: RetroCoreLabs/RetroTerm

SECURITY.md

Security policy

Reporting a vulnerability

Please do not open a public issue for a security problem.

Use GitHub's private reporting instead: go to the Security tab of this repository and choose Report a vulnerability. That opens a private advisory visible only to the maintainers, and it lets us work on a fix and publish it together with the disclosure.

What helps, in rough order of usefulness:

  • what an attacker gains - read a file they should not, crash the process, run code;
  • the shortest input that triggers it. A capture, a disk image or a byte sequence is worth far more than a description of one;
  • which component and which version or commit;
  • whether it needs a valid session, a local account, or nothing at all.

You will get an acknowledgement. This is a small project maintained in spare time, so please do not read a slow reply as a lack of interest - if a week passes with no word, send a reminder through the same advisory.

What is in scope

RetroTerm connects to remote hosts and renders whatever they send. The terminal emulators are the part worth attacking: every byte from the host goes through the escape-sequence parser and the emulator state machines, and a host that is hostile or simply broken must not be able to do more than draw a bad screen. In scope: a reachable memory-safety bug in the parser or an emulator, an unbounded allocation driven by a parameter in an escape sequence, an infinite loop on a malformed sequence, and any way a host can make the terminal send back data it did not type - the query and report sequences (Device Attributes, cursor position, the TDV report commands) are the classic route for that.

The MCP server listens on http://127.0.0.1:5715/mcp and lets a client type into any session and run scripts. It is bound to the loopback address on purpose. Anything that lets a remote machine reach it, or lets a web page in a browser on the same machine drive it, is in scope and serious.

SSH host key handling is trust-on-first-use. A way to make the client accept a changed host key without the warning is in scope. Kermit file transfer writes files the remote end names: a path that escapes the chosen directory is in scope.

Also in scope: anything in this repository that handles a file or a stream it did not create - a disk image, a configuration file, a capture, a saved session.

What is not in scope

  • The age of the protocols themselves. Telnet, a serial line, Kermit and the ND-100 gateway have no authentication, no encryption and no integrity checking worth the name (SSH is the one exception). That is what they were; reproducing them faithfully is the purpose of this project, not a defect. Do not run any of it on a network you do not control, and do not expose a port of it to the internet.
  • A report generated by a scanner with no demonstration that the finding is reachable.
  • Denial of service by sending an unreasonable volume of traffic.
  • Anything requiring the attacker to already be able to run code as the user.

Supported versions

The most recent tagged release is what is supported - at the time of writing v1.10.26.9 - together with the main branch it was cut from. Older releases are not patched.

Credit

Unless you ask otherwise, you will be named in the advisory and in the release notes for the fix.

There aren't any published security advisories