Skip to content

Security: HackingRepo/sandssrf-js

SECURITY.md

Security Policy

We thank's to all researchers for reporting vulns in sandssrf, we fully appreciate in sandssrf. the most thing is read README To see things like proxy are not considered in scope of sandssrf

here is things out of scope includes:

  1. Vulns in third party libraires
  2. Misuse of SandSSRF, read README, documents that exact thing

Before to report a vuln do the following

  1. Make sure use latest version, at least testing in both latest and master is good thing however not required
  2. How that is rare or common, explain, if requires weird sandbox config
  3. Use CVSS v4 for the score
  4. Alywas include a POC

To report a vuln use relunsec@insitetech.jp email, we welcome all security reports, will put list of reporters in the above section

Researchers who find vulns in our project:

  1. TBD

There aren't any published security advisories