SpecterLang is experimental research software. It is not a hardened sandbox and must not be used as a security boundary for hostile scripts.
FFI, JIT, AOT, reflection, native addresses, and inline assembly can reach native process capabilities. The language permission model reduces accidental access but does not establish isolation from a determined attacker.
Use the repository's private security advisory flow when available. If private advisories are unavailable, open a public issue that asks the maintainer to establish a private reporting channel, but do not include exploit details in that issue.
Include the affected revision, execution mode, smallest reproducer, expected behavior, observed behavior, and impact. State whether the issue reproduces in the interpreter, JIT, AOT, or more than one mode.