Skip to content

Security: y0f/asura

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Do not open a public issue.

Email: asura@red.tf

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

You will receive a response within 48 hours. We will coordinate disclosure and credit you (unless you prefer anonymity).

Supported Versions

Version Supported
latest Yes

Scope

  • Authentication bypass
  • API key exposure
  • SQL injection
  • Remote code execution (especially command-type monitors)
  • Privilege escalation
  • Information disclosure

There aren't any published security advisories