Skip to content

Security: xdrew87/CanaryNet

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest (main)
Older releases

Reporting a Vulnerability

Please do NOT open a public GitHub issue for security vulnerabilities.

To report a security issue privately:

  1. Email: security@osintintelligence.xyz
  2. Subject line: [SECURITY] CanaryNet - <brief description>
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fix (optional)

We aim to respond within 48 hours and will work with you to understand and resolve the issue promptly.

Scope

The following are in scope:

  • Authentication bypass
  • Remote code execution
  • SQL injection
  • Sensitive data exposure
  • Privilege escalation in the dashboard API

The following are out of scope:

  • Denial of service attacks
  • Issues requiring physical access to the server
  • Social engineering

Disclosure Policy

We follow responsible disclosure. Once a fix is released, we will credit the reporter (with their permission) in the release notes.

Thank you for helping keep CanaryNet and its users safe.

There aren't any published security advisories