Report it privately through GitHub: open the repository's Security tab and choose Report a vulnerability, or go to https://github.com/khiops/lasterm/security/advisories/new.
Do not open a public issue for a vulnerability. Include the lasterm version, the platform (Windows version, remote host OS), the steps that reproduce it and what an attacker gains.
You get an acknowledgement within 7 days. The fix ships in the next release, and the advisory is published with it, crediting you unless you ask otherwise.
Only the latest release receives security fixes.
The hub, the agent, and the desktop and web clients in this repository. The threat
model, still a draft, is in docs/SECURITY.md.