Thank you for helping keep CueVote and its users safe.
If you believe you have discovered a security vulnerability in CueVote, please report it privately. Do not open a public GitHub issue.
Contact: security@cuevote.com
When reporting, please include:
- A clear description of the issue
- Steps to reproduce, with a proof-of-concept if possible
- The version, branch, or commit affected
- Any potential impact you have identified
- Your contact information for follow-up
CueVote is maintained by a small team. We do our best to respond promptly:
- Acknowledgement: within 7 days
- Initial assessment: within 14 days
- Fix timeline: depends on severity; critical issues are prioritised
We will keep you informed of progress and are happy to credit you in the fix announcement, if you wish.
In scope:
- The CueVote web application at https://cuevote.com
- The backend WebSocket server and database layer in this repository
- The frontend client code in this repository
- Authentication and session handling
- Handling and privacy of stored user data
Out of scope:
- Third-party services we use (Cloudflare, Google/YouTube) — please report directly to the respective vendor
- Denial-of-service attacks
- Social engineering of CueVote users or staff
- Physical attacks
- Vulnerabilities requiring physical access to a user's device
- Theoretical issues without a demonstrable security impact
- Findings from automated scanners without a proof-of-concept
We support good-faith security research. If you make a reasonable effort to comply with this policy during your research, we will:
- Consider your research authorised under this policy
- Work with you to understand and resolve the issue
- Not pursue legal action against you for your research
Please:
- Make a good-faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
- Use the reported issue only to the extent necessary to confirm its presence
- Do not disclose the issue publicly until we have had a reasonable opportunity to address it
We follow coordinated disclosure principles: once a fix is available, we are happy to publicly acknowledge your contribution, if you wish.