Skip to content

Security: Aswellle/LightAblum

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not report security vulnerabilities through public GitHub issues.

Please disclose vulnerabilities privately by emailing the maintainers. We will:

  • Acknowledge receipt within 48 hours
  • Provide an estimated fix timeline within 7 days
  • Credit you in the release notes (unless you prefer anonymity)

Scope

  • SQL injection via IPC commands
  • Path traversal in file scanner
  • Arbitrary code execution via sidecar process
  • Private album password bypass

Out of Scope

  • Issues in dependencies (report upstream)
  • Denial of service on local machine

There aren't any published security advisories