Cyber Info values the work of security researchers who help us protect our community, projects, and services. We encourage responsible, good-faith vulnerability research and coordinated disclosure.
This file is the default security policy for Cyber Info repositories that do not provide their own SECURITY.md. If a repository has a separate security policy, that repository-specific policy takes precedence.
Please do not open a public GitHub issue, discussion, or pull request for a suspected vulnerability.
Report vulnerabilities through one of these channels:
- Preferred: Cyber Info Vulnerability Disclosure Program
- Email: security@cyber.info
- PGP key: https://cyber.info/pgp-key.txt
Use our PGP key when a report or its attachments contain sensitive information.
A useful report should include, when available:
- The affected repository, service, URL, component, and version or commit
- A clear description of the vulnerability and its potential impact
- Reproduction steps or a minimal proof of concept
- Relevant logs, screenshots, requests, responses, or other supporting evidence
- Any conditions required to reproduce the issue
- Suggested remediation, if known
- Your preferred contact information and any disclosure plans
Please submit one vulnerability per report unless multiple findings must be combined to demonstrate their impact.
When conducting security research:
- Test only systems and data that you are authorized to access.
- Make a good-faith effort to avoid privacy violations, data loss, service disruption, and harm to users.
- Access, modify, retain, or share only the minimum data necessary to demonstrate the issue.
- Do not use social engineering, phishing, physical attacks, denial-of-service techniques, or destructive testing.
- Do not establish persistence or pivot to unrelated systems.
- Stop testing and report the issue promptly if you encounter sensitive or personal data.
- Keep vulnerability details confidential while we investigate and coordinate remediation and disclosure.
Our complete scope, rules, exclusions, safe-harbor terms, and disclosure process are maintained in the Cyber Info Vulnerability Disclosure Program. That policy governs if it conflicts with this summary.
We will review reports submitted through the designated channels and work with researchers to understand and address valid findings. Response and remediation times depend on the severity and complexity of the issue.
Please allow us a reasonable opportunity to investigate and remediate a vulnerability before publishing details. Coordinate any public disclosure with our security team.
Eligible researchers may be recognized in our Hall of Fame, subject to our disclosure policy and the researcher's consent. Submission of a report does not create an entitlement to payment or another reward.
Our canonical machine-readable security contact information is available at: