Environment
Hi,
I have identified a security vulnerability in MagicMirror² that could affect users running the application in server mode (exposed to a network).
I'd like to follow responsible disclosure practices and share the details privately before any public release.
Could you please:
I will keep the details private until a fix is available or 90 days have passed (whichever comes first), in line with standard responsible disclosure timelines.
Thank you.
Which start option are you using?
node --run start
Are you using PM2?
No
Module
None
Have you tried disabling other modules?
Have you searched if someone else has already reported the issue on the forum or in the issues?
What did you do?
Found a security vulnerability
What did you expect to happen?
Enable https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability on this repository.
OR
Possibility to share vulnerability details privately.
What actually happened?
n/a
Additional comments
No response
Participation
Environment
Hi,
I have identified a security vulnerability in MagicMirror² that could affect users running the application in server mode (exposed to a network).
I'd like to follow responsible disclosure practices and share the details privately before any public release.
Could you please:
I will keep the details private until a fix is available or 90 days have passed (whichever comes first), in line with standard responsible disclosure timelines.
Thank you.
Which start option are you using?
node --run start
Are you using PM2?
No
Module
None
Have you tried disabling other modules?
Have you searched if someone else has already reported the issue on the forum or in the issues?
What did you do?
Found a security vulnerability
What did you expect to happen?
Enable https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability on this repository.
OR
Possibility to share vulnerability details privately.
What actually happened?
n/a
Additional comments
No response
Participation