Please do not open a public GitHub issue for security vulnerabilities.
Report them privately by email: security@septm.xyz
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
I will acknowledge your report within 72 hours and aim to release a fix within 14 days depending on severity.
In scope:
- Authentication and session handling
- API endpoints and authorization
- Data exposure or injection vulnerabilities
Out of scope:
- Denial of service attacks
- Issues requiring physical access to the server
- Vulnerabilities in third-party dependencies (report those upstream)
I follow coordinated disclosure. Please allow time for a fix to be released before making a vulnerability public.