CloudBank handles personal financial data, so we take security seriously.
Please do not open a public issue for security vulnerabilities.
Instead, report privately via one of:
- GitHub's private vulnerability reporting (preferred), or
- email to the maintainer at the address on the GitHub profile.
Please include:
- a description of the issue and its impact,
- steps to reproduce (a proof of concept if possible),
- affected version / commit.
We aim to acknowledge reports within a few days and will keep you informed about the fix and disclosure timeline. Coordinated disclosure is appreciated.
Security fixes target the latest stable release (the :main container tag) and the current main branch. Older tagged releases are not maintained — upgrade to the latest before reporting.
In scope: authentication/session handling, wallet data isolation between users, injection, CSRF/XSS, secrets at rest, and container hardening. Out of scope: issues requiring a pre-compromised host or physical access to the server.
The public demo is in scope for anything that lets one visitor reach another's account or the host. Its deliberate resets and limits are not vulnerabilities, and please don't load-test it.