Please do not open a public issue for an unpatched vulnerability.
Use GitHub's private vulnerability reporting. If it is unavailable, open an issue asking for a private way to get in touch. Do not include details about the vulnerability in that issue.
In the private report, include the affected deployment or commit, browser and operating system, steps to reproduce the problem, its impact, and any workaround you know of. We will coordinate a fix and agree on when to publish the details.
Security fixes are made against the latest version deployed at basekit.ras.sh and the current main branch.
BaseKit has no backend, accounts, database, or uploaded files. Geometry and exports stay in the browser. Reports about crafted configuration values, browser-side file generation, bundled dependencies, or deployment configuration are still welcome.