PersonalTrader handles broker account data and can submit orders. Please treat vulnerabilities that could cross an account or environment boundary, expose sensitive data, bypass an order gate, duplicate a send, corrupt financial evidence, or misrepresent broker state as high impact.
Before the first public release, only the latest commit on the repository's primary branch is considered for security fixes. Preview packages and older commits may not receive patches.
Do not open a public issue for a suspected vulnerability or include credentials, account identifiers, order evidence, database files, or exploit details in a public discussion.
Once the repository is hosted on GitHub, use its private Security → Report a vulnerability flow. If private vulnerability reporting is not enabled, contact the repository owner through a private channel listed on the owner's GitHub profile and include only enough information to establish a secure follow-up channel.
Include:
- the affected version or commit;
- the target involved: Simulator, Paper, or Live;
- the security boundary that can be crossed;
- minimal reproduction steps using Simulator or mocked data where possible;
- the potential impact; and
- any suggested mitigation.
Never test a vulnerability by placing an unauthorized or unnecessary Live order, accessing another person's account, or disrupting broker services.
The maintainer will aim to acknowledge a complete private report within seven days. Resolution time depends on severity, reproducibility, and whether the issue is in PersonalTrader, TWS API behavior, local configuration, or broker infrastructure.
IBKR account compromise or suspicious brokerage activity should also be reported directly to Interactive Brokers through its official support and security channels.