Files
EchoHub/SECURITY.md
T

870 B
Raw Blame History

Security Policy

Reporting a vulnerability

If you believe youve found a security vulnerability in EchoHub (for example: auth bypass, token leakage, file upload validation bypass, RCE, etc.), please do not open a public GitHub issue.

Preferred: use GitHubs private vulnerability reporting ("Report a vulnerability"):

If that link is unavailable for your account, contact the maintainer via GitHub:

What to include

  • A clear description of the issue and potential impact
  • Reproduction steps or a proof-of-concept
  • Affected versions / commit SHA
  • Any relevant logs (with secrets removed)

Disclosure

Ill acknowledge receipt, investigate, and work on a fix. Please avoid publicly disclosing details until a fix is available.