mirror of
https://github.com/RedWizardsLab/EchoHub.git
synced 2026-09-04 08:36:11 +02:00
870 B
870 B
Security Policy
Reporting a vulnerability
If you believe you’ve found a security vulnerability in EchoHub (for example: auth bypass, token leakage, file upload validation bypass, RCE, etc.), please do not open a public GitHub issue.
Preferred: use GitHub’s private vulnerability reporting ("Report a vulnerability"):
If that link is unavailable for your account, contact the maintainer via GitHub:
What to include
- A clear description of the issue and potential impact
- Reproduction steps or a proof-of-concept
- Affected versions / commit SHA
- Any relevant logs (with secrets removed)
Disclosure
I’ll acknowledge receipt, investigate, and work on a fix. Please avoid publicly disclosing details until a fix is available.