We thank's to all researchers for reporting vulns in sandssrf, we fully appreciate in sandssrf. the most thing is read README To see things like proxy are not considered in scope of sandssrf
here is things out of scope includes:
- Vulns in third party libraires
- Misuse of SandSSRF, read README, documents that exact thing
Before to report a vuln do the following
- Make sure use latest version, at least testing in both latest and master is good thing however not required
- How that is rare or common, explain, if requires weird sandbox config
- Use CVSS v4 for the score
- Alywas include a POC
To report a vuln use relunsec@insitetech.jp email, we welcome all security reports, will put list of reporters in the above section
Researchers who find vulns in our project:
- TBD