Skip to main content

Security Policy

Reporting a Vulnerability

Please DO NOT report security vulnerabilities through public GitHub issues.

Preferred Method

Report via GitHub Security Advisories:

  1. Navigate to the Security tab
  2. Click "Report a vulnerability"
  3. Provide detailed information

What to Include

  • Type of vulnerability (XSS, SQL injection, auth bypass, etc.)
  • Affected component (frontend, backend, agent, specific module)
  • Steps to reproduce
  • Proof of concept (if applicable)
  • Potential impact
  • Suggested fix (if available)

Response Timeline

ActionTimeline
Initial acknowledgmentWithin 48 hours
Initial assessmentWithin 7 days
Status updateEvery 14 days
Fix developmentDependent on severity
Public disclosureAfter fix is released

Severity Classification

SeverityDescriptionExample
CriticalFull system compromiseRCE, auth bypass
HighSignificant data exposureSQL injection, data leak
MediumLimited impact, user interactionStored XSS, CSRF
LowMinimal impactInfo disclosure

Supported Versions

VersionSupported
1.x.x (latest)Yes