Findings
Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.
In-house, code-backed catalog. Status vocabulary: Confirmed, Mitigated, Accepted, Info, Out of scope. This draft describes the app as it is now — resolved Critical/High/Medium remediations are not listed.
Critical
None in this draft.
High
None in this draft.
Medium
| ID | Impact | Status | Where |
|---|---|---|---|
| GLITR-2026-001 | Dual-ratchet concurrent-init tie-break is a custom product rule | Confirmed | Cryptography |
| GLITR-2026-002 | Groups historically pairwise-fan-out plaintext; N-party GroupSession is the group ratchet | Mitigated | Cryptography; MLS pairwise review |
| GLITR-2026-003 | WebRTC ICE/media may still use public STUN or direct paths when Tor is on | Confirmed | Tor; Live and WebRTC |
| GLITR-2026-021 | MLS façade lifecycle gaps (self-update / remove) blocked faithful group PCS claims | Mitigated | MLS pairwise review |
Low
| ID | Impact | Status | Where |
|---|---|---|---|
| GLITR-2026-004 | Linux desktop WebKit auto-allows camera / mic / device-info | Confirmed | Live and WebRTC |
| GLITR-2026-005 | Mobile Arti storage uses dangerously_trust_everyone | Confirmed | Tor |
| GLITR-2026-006 | WebView bridges use document::eval (CSP allows unsafe-eval) | Confirmed | Client and storage |
| GLITR-2026-007 | Git commits use a fixed db@local committer | Confirmed | Git mailbox |
| GLITR-2026-022 | MLS identity/group JSON export is secret material; must stay sealed at rest | Confirmed | MLS pairwise review |
| GLITR-2026-023 | MLS key-package refresh / glare alignment needs explicit product tests | Mitigated | MLS pairwise review |
Accepted leftovers
Already named on Residual risk.
| ID | Impact | Status | Where |
|---|---|---|---|
| GLITR-2026-008 | Git host sees activity, access, sizes, and IPs | Accepted | Git mailbox |
| GLITR-2026-009 | wu1: / on1: invites are plaintext out of band | Accepted | Identity and pairing |
| GLITR-2026-010 | Messenger is closed-source; no independent audit | Accepted | This page; Residual risk |
| GLITR-2026-011 | Peer RPC may list outbound / profile-public / receipts as ciphertext | Accepted | Live and WebRTC |
Info and non-findings
| ID | Note | Status | Where |
|---|---|---|---|
| GLITR-2026-012 | Chat text renders as an escaped text node | Info | Client and storage |
| GLITR-2026-013 | GUI and TUI do not persist the encryption password or git tokens in glitr:connect | Info | Client and storage |
| GLITR-2026-014 | Cascade v3 only; fail-closed without protocolBundles; signed SPKs; OTPK pool | Info | Cryptography |
| GLITR-2026-015 | Safety numbers cover RSA SPKI plus protocolBundles | Info | Identity and pairing |
| GLITR-2026-016 | No Web Push subscription in whatsup | Info | Client and storage |
| GLITR-2026-017 | Gallery OpenRelay TURN credentials are not the Glitr / whatsup default ICE set | Out of scope | Live and WebRTC |
| GLITR-2026-018 | Per-contact git/tor/webrtc prefs; STUN dropdown; onion-preferred WebRTC signaling | Info | Live and WebRTC |
| GLITR-2026-019 | Hello Match/Store promotes contact to active for git and live send | Info | Identity and pairing |
| GLITR-2026-020 | Production PWA injects CSP; isomorphic-git is same-origin under assets/vendor/ | Info | Client and storage |
| GLITR-2026-024 | Coarse mls-core errors avoid oracle leakage; cascade stays fail-closed | Info | MLS pairwise review |
How to cite an ID
Use the GLITR-2026-NNN form in issues and PRs. Narrative pages link back here.
