Only the latest commit on the main branch of this repository receives security fixes.
Please do not open a public issue for security problems.
Report privately via GitHub: Report a vulnerability (the "Security" tab of this repository → "Report a vulnerability").
Please include:
- what is affected (the web page, or the local server
server.mjs), with the browser / OS and version - steps to reproduce, and a sample MIDI or SFZ file if one is needed
- the impact you expect
Responses may take a while and no response time is guaranteed. Progress will be shared in the advisory, and I am happy to credit you there unless you prefer otherwise.
midi-kbd runs entirely in the browser and only loads files from its own origin. Issues that break this are especially important, for example:
- a crafted MIDI file that runs script in the page (XSS) or bypasses the Content Security Policy
- the page sending any request to a third-party origin
- the local server (
server.mjs) serving files outside the project,sfz/and the VexFlow build, or being reachable from other machines
Out of scope: problems that require a compromised browser or device, and reports from automated scanners without a demonstrated impact.
脆弱性は公開のIssueではなく、上記の Report a vulnerability(リポジトリのSecurityタブ)から非公開でご報告ください。日本語で構いません。お返事までお時間をいただくことがあります。