Security fixes are applied to the latest release on the default branch. Older releases may not receive patches.
Do not open a public issue for security problems.
Report privately through one of:
- GitHub Security Advisories for this repository (Security tab -> Report a vulnerability)
- Email: ivan@quad4.io
Include enough detail to reproduce the issue: affected version or commit, configuration, steps, and impact. Screenshots or proof-of-concept scripts help when they are safe to share privately.
- Acknowledgement within a few business days
- A fix or mitigation plan when the report is accepted
- Coordinated disclosure after a release is available, unless you ask us not to credit you
Please give us reasonable time to ship a fix before any public discussion.
In scope: Athenaeum server, web UI, install and deploy scripts in this repository, and default configuration that can expose hosts or data.
Out of scope: third-party dependencies reported only against upstream, local misconfiguration, and denial-of-service from unbounded legitimate traffic unless there is a clear, fixable bug.
Good-faith research that follows this policy and avoids privacy harm, data destruction, and service disruption is welcome. Do not access other users' data or keep copies of sensitive information beyond what is needed to demonstrate the issue.