Skip to content

Security: loewenmaehne/cuevote

Security

SECURITY.md

Security Policy

Thank you for helping keep CueVote and its users safe.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in CueVote, please report it privately. Do not open a public GitHub issue.

Contact: security@cuevote.com

When reporting, please include:

  • A clear description of the issue
  • Steps to reproduce, with a proof-of-concept if possible
  • The version, branch, or commit affected
  • Any potential impact you have identified
  • Your contact information for follow-up

What to Expect

CueVote is maintained by a small team. We do our best to respond promptly:

  • Acknowledgement: within 7 days
  • Initial assessment: within 14 days
  • Fix timeline: depends on severity; critical issues are prioritised

We will keep you informed of progress and are happy to credit you in the fix announcement, if you wish.

Scope

In scope:

  • The CueVote web application at https://cuevote.com
  • The backend WebSocket server and database layer in this repository
  • The frontend client code in this repository
  • Authentication and session handling
  • Handling and privacy of stored user data

Out of scope:

  • Third-party services we use (Cloudflare, Google/YouTube) — please report directly to the respective vendor
  • Denial-of-service attacks
  • Social engineering of CueVote users or staff
  • Physical attacks
  • Vulnerabilities requiring physical access to a user's device
  • Theoretical issues without a demonstrable security impact
  • Findings from automated scanners without a proof-of-concept

Safe Harbor

We support good-faith security research. If you make a reasonable effort to comply with this policy during your research, we will:

  • Consider your research authorised under this policy
  • Work with you to understand and resolve the issue
  • Not pursue legal action against you for your research

Please:

  • Make a good-faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
  • Use the reported issue only to the extent necessary to confirm its presence
  • Do not disclose the issue publicly until we have had a reasonable opportunity to address it

Coordinated Disclosure

We follow coordinated disclosure principles: once a fix is available, we are happy to publicly acknowledge your contribution, if you wish.

There aren't any published security advisories