Skip to content

Security: Josbrig/SMB_Mounter

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you find a security vulnerability in SMB Mounter (e.g. a way to read stored credentials, a weakness in the network scan, or an issue with permission handling), please do not report it as a public GitHub issue.

Instead, contact the repository owner directly via GitHub (a private message or the contact form linked in the GitHub profile). If possible, please include:

  • The affected program version/commit
  • A short description of the vulnerability and its impact
  • Steps to reproduce, if available

Handling credentials in process memory

When connecting network drives, SMB passwords are passed exclusively via the Windows API WNetAddConnection2 (via pywin32) as a function parameter in process memory – never as a command line argument of an external process (e.g. net.exe). This means they are not briefly visible to other processes with sufficient privileges via process inspection tools (Process Explorer, WMI Win32_Process.CommandLine, ETW tracing).

Scope

The following are considered security vulnerabilities in particular:

  • Storage or transmission of credentials (usernames, passwords) outside Windows Credential Manager
  • Ways to gain access to systems through the program that you're not authorized to access
  • Unintended data transmission to third parties beyond the MAC vendor lookup described in PRIVACY.md

The following are not considered security vulnerabilities in the strict sense: general bugs, UI issues, or compatibility questions – please file a regular issue for those.

Supported versions

Since this is a single-maintainer project without parallel maintained version branches, security fixes are provided exclusively for the main branch.

There aren't any published security advisories