Security
Security
Report a problem
Found a vulnerability? Please write to support@houjun.dev with the subject “Image MLX Lab security” before telling anyone else, and do not open a public issue for it. Say what you found, how to reproduce it and which version (commit) you used. We will acknowledge your report, keep you informed, and credit you when it is fixed if you wish. There is no bug bounty.
Machine-readable contact: security.txt; this page is the policy it points to.
How Image MLX Lab is built to be safe
- This Mac only. The workbench (127.0.0.1:18080) and the model server (127.0.0.1:11234) listen on the local machine only. There is no network access mode.
- Other websites cannot drive it. The workbench accepts changes only as JSON from its own page: requests from other origins and cross-site requests are refused, and it adds no CORS headers. Requests naming any other host are refused, which blocks DNS-rebinding attacks.
- Only what the page needs is served. The interface files and the images in your library — not the project folder, its Git data, logs, settings or performance records.
- Files stay in their place. Deleting or overwriting is allowed only for images directly inside the workbench's own library folders; any other path is refused.
- The mask is enforced in code. An AI local edit is composited through the frozen full-size mask and rejected if any pixel outside the mask changed.
- Pinned versions. Setup downloads the model at a fixed revision and builds the runtime from a fixed commit, then applies the project's patch only if it matches exactly.
- Nothing private is published. A release check refuses to publish working images, logs or local paths; only reviewed demo images are allowed into the repository.
This website
Static pages over HTTPS with a strict content security policy: no scripts, no third-party resources, no cookies.
Last updated 28 September 2026.