Skip to content

Security: cubeindex-project/CubeIndex

SECURITY.md

Security Policy

Supported Versions

Only the latest deployment (commit) of CubeIndex is supported for security vulnerability reports.

Version Supported
Latest deployment
Older deployments

Reporting a Vulnerability

If you discover a security vulnerability in CubeIndex, do not create a public GitHub issue or publicly disclose the vulnerability.

Instead, report it privately through the GitHub Security Advisories page:

  1. Click "Report a vulnerability".
  2. Describe the vulnerability and its potential impact.
  3. Include steps to reproduce the issue, if possible.
  4. Include the affected component, page, endpoint, or version.
  5. Include a proof of concept if one is necessary to demonstrate the issue.

Please avoid including sensitive data belonging to other users in your report.

What to Expect

We will make a reasonable effort to:

  • Acknowledge your report within a few business days.
  • Investigate and confirm the vulnerability.
  • Keep you informed about significant progress.
  • Release a fix as soon as reasonably possible.

Resolution time may vary depending on the severity and complexity of the issue.

Coordinated Disclosure

Please do not publicly disclose a vulnerability until a fix has been released or disclosure has been coordinated with the CubeIndex maintainers.

After the issue has been resolved, we are happy to discuss appropriate public disclosure and credit for the reporter.

Scope

Security issues affecting the current CubeIndex deployment or its source code are in scope.

Examples may include:

  • Authentication or authorization issues
  • Exposure of sensitive information
  • Cross-site scripting (XSS)
  • Injection vulnerabilities
  • Server-side request forgery (SSRF)
  • Access-control bypasses
  • Vulnerable application logic
  • Security issues caused by project dependencies

Reports about unsupported or older deployments may not be investigated unless the issue also affects the latest deployment.

Safe Harbor

We welcome good-faith security research conducted in accordance with this policy.

Please:

  • Avoid accessing, modifying, or deleting data that does not belong to you.
  • Avoid disrupting CubeIndex or its users.
  • Stop testing and contact us if you encounter sensitive user data.
  • Report discovered vulnerabilities privately and give us reasonable time to address them.

Research performed in good faith and consistent with this policy will not be considered malicious by the CubeIndex project.

Thank You

We appreciate responsible security researchers who help make CubeIndex safer for everyone.

There aren't any published security advisories