Skip to content

Security: TrueFurina/passive-recon

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

Please report security vulnerabilities by opening a private security advisory at:

https://github.com/TrueFurina/passive-recon/security/advisories/new

We will respond within 48 hours and provide a timeline for the fix.

Scope

  • Code injection / command injection
  • SSRF in data source connectors
  • Credential leakage in logs
  • Compliance bypass of the fail-closed guardrail

Out of Scope

  • Brute force attacks against third-party APIs used by this tool
  • Vulnerabilities in third-party services consumed by the tool

There aren't any published security advisories