Responsible disclosure
Found a security problem in Orbiter? Please tell us privately first. Fixes ship as normal npm releases, and every fixed issue is published as a GitHub security advisory.
How to report
- Open a private security advisory on GitHub (preferred, it stays between you and the maintainers).
- Or write to post@abteilung83.com.
Helpful in a report: affected package and version, steps to reproduce, and what an attacker gains. Please don't test against sites you don't own, and give us a chance to ship a fix before you publish details.
What happens next
- We confirm receipt and reproduce the issue.
- We fix it and release new package versions.
- We publish a GitHub security advisory and credit you in the form you prefer, unless you want to stay anonymous.
Thanks
Thank you to Adrian Wilczek for responsibly reporting three vulnerabilities: a stored XSS in the inbox, a collection permission bypass and a media path traversal. All three are fixed and published.
Published advisories
| Advisory | Issue | Fixed in | Reported by |
|---|---|---|---|
| GHSA-wv82-8593-g3c5 | Stored XSS in the inbox | admin 0.3.82 | Adrian Wilczek |
| GHSA-w3h3-6g4r-hxc5 | Collection permission bypass (singletons and export) | admin 0.3.82 | Adrian Wilczek |
| GHSA-r4r2-gxr8-p3vc | Media path traversal | core 0.3.15 | Adrian Wilczek |
| GHSA-vvp4-5qxq-47r8 | Stored XSS through media content type | admin 0.3.86, integration 0.3.21 | Internal audit |
| GHSA-7jg7-w84v-wg8m | SSRF in media import by URL | admin 0.3.86 | Internal audit |
| GHSA-5h4q-fqfp-gq9w | Content API returned drafts to anonymous callers | integration 0.3.21 | Internal audit |
Our contact details are also available machine-readable at /.well-known/security.txt.