Skip to content

Security: valorisa/ShellFromBrowser

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest
< latest

Reporting a Vulnerability

If you discover a security vulnerability in ShellFromBrowser, please report it responsibly:

  1. Do NOT open a public issue for security vulnerabilities
  2. Use GitHub Security Advisories to report privately
  3. Or email the maintainer directly

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response timeline

  • Acknowledgment: within 72 hours
  • Initial assessment: within 1 week
  • Fix or mitigation: depends on severity, typically within 30 days

Scope

The following are in scope:

  • Authentication bypass
  • Remote code execution
  • Path traversal
  • WebSocket security issues
  • JWT token vulnerabilities
  • Cross-site scripting (XSS)

Thank you for helping keep ShellFromBrowser secure.

There aren't any published security advisories