Only the latest deployment (commit) of CubeIndex is supported for security vulnerability reports.
| Version | Supported |
|---|---|
| Latest deployment | ✅ |
| Older deployments | ❌ |
If you discover a security vulnerability in CubeIndex, do not create a public GitHub issue or publicly disclose the vulnerability.
Instead, report it privately through the GitHub Security Advisories page:
- Click "Report a vulnerability".
- Describe the vulnerability and its potential impact.
- Include steps to reproduce the issue, if possible.
- Include the affected component, page, endpoint, or version.
- Include a proof of concept if one is necessary to demonstrate the issue.
Please avoid including sensitive data belonging to other users in your report.
We will make a reasonable effort to:
- Acknowledge your report within a few business days.
- Investigate and confirm the vulnerability.
- Keep you informed about significant progress.
- Release a fix as soon as reasonably possible.
Resolution time may vary depending on the severity and complexity of the issue.
Please do not publicly disclose a vulnerability until a fix has been released or disclosure has been coordinated with the CubeIndex maintainers.
After the issue has been resolved, we are happy to discuss appropriate public disclosure and credit for the reporter.
Security issues affecting the current CubeIndex deployment or its source code are in scope.
Examples may include:
- Authentication or authorization issues
- Exposure of sensitive information
- Cross-site scripting (XSS)
- Injection vulnerabilities
- Server-side request forgery (SSRF)
- Access-control bypasses
- Vulnerable application logic
- Security issues caused by project dependencies
Reports about unsupported or older deployments may not be investigated unless the issue also affects the latest deployment.
We welcome good-faith security research conducted in accordance with this policy.
Please:
- Avoid accessing, modifying, or deleting data that does not belong to you.
- Avoid disrupting CubeIndex or its users.
- Stop testing and contact us if you encounter sensitive user data.
- Report discovered vulnerabilities privately and give us reasonable time to address them.
Research performed in good faith and consistent with this policy will not be considered malicious by the CubeIndex project.
We appreciate responsible security researchers who help make CubeIndex safer for everyone.