Docs

Responsible disclosure

Found a security problem in Orbiter? Please tell us privately first. Fixes ship as normal npm releases, and every fixed issue is published as a GitHub security advisory.

How to report

Helpful in a report: affected package and version, steps to reproduce, and what an attacker gains. Please don't test against sites you don't own, and give us a chance to ship a fix before you publish details.

What happens next

  1. We confirm receipt and reproduce the issue.
  2. We fix it and release new package versions.
  3. We publish a GitHub security advisory and credit you in the form you prefer, unless you want to stay anonymous.

Thanks

Thank you to Adrian Wilczek for responsibly reporting three vulnerabilities: a stored XSS in the inbox, a collection permission bypass and a media path traversal. All three are fixed and published.

Published advisories

AdvisoryIssueFixed inReported by
GHSA-wv82-8593-g3c5Stored XSS in the inboxadmin 0.3.82Adrian Wilczek
GHSA-w3h3-6g4r-hxc5Collection permission bypass (singletons and export)admin 0.3.82Adrian Wilczek
GHSA-r4r2-gxr8-p3vcMedia path traversalcore 0.3.15Adrian Wilczek
GHSA-vvp4-5qxq-47r8Stored XSS through media content typeadmin 0.3.86, integration 0.3.21Internal audit
GHSA-7jg7-w84v-wg8mSSRF in media import by URLadmin 0.3.86Internal audit
GHSA-5h4q-fqfp-gq9wContent API returned drafts to anonymous callersintegration 0.3.21Internal audit

Our contact details are also available machine-readable at /.well-known/security.txt.

Last updated Edit this page on GitHub ↗