This repository is a demo project and does not provide long-term support guarantees. That said, security issues will be fixed as quickly as possible once confirmed.
Please do not open public GitHub issues for vulnerabilities.
Report privately by email:
Include:
- A clear description of the issue
- Steps to reproduce
- Impact and suggested fix (if known)
If you don't have a private channel set up yet, create a GitHub issue with only: "Security report requested" and ask for a private contact method.
In scope:
- Authentication/authorization bypass
- CSRF/session issues
- Sensitive data leakage
- Remote code execution / SSRF-style vulnerabilities
Out of scope:
- Issues requiring local access to your own machine
- Social engineering
This project is intended for local use, demos, and experimentation. It is not audited or certified for compliance use.