If you discover a vulnerability in Orivex, please disclose it responsibly.
Email security@orivex.network with:
- A clear description of the issue and its impact.
- Reproduction steps, screenshots, or a proof-of-concept where possible.
- The commit hash, branch, or deployed version you observed the issue on.
Please do not open a public GitHub issue for undisclosed vulnerabilities.
- An acknowledgement within 2 business days.
- A triage assessment within 5 business days, including a severity estimate.
- Coordinated disclosure timing — we'll align a fix release with you before any public write-up.
- The Next.js app in this repository and its dependencies.
- The Orivex contracts in
Orivex-Contracts. - The Orivex backend service in
Orivex-Backend.
- Third-party platforms we link out to (please report upstream).
- Hypothetical issues without a working reproduction.
Thank you for keeping Orivex learners safe.