Write to dev@dworkspace, or open a private advisory through GitHub's report a vulnerability form. Please do not open a public issue for a security problem.
You will get an acknowledgement within 72 hours. dworkspace is maintained by one person, so a fix takes as long as it takes. You will be told what is happening rather than left in silence. There is no bounty programme.
Please include what you found, how to reproduce it, and what an attacker could do with it. A proof of concept helps and is never required.
The server, the frontend, the MCP surface, the desktop application, and the install script in this repository.
Out of scope: an instance somebody else runs, and how they have configured it. If you found something on a dworkspace instance that is not ours, tell its operator.
Do not test against instances you do not own. A self-hosted product is easy to run locally with one binary and one command, and that is the right place to look.
The latest release. dworkspace is early and moves quickly; there are no long-term support branches yet.