| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Use GitHub's private vulnerability reporting. It is the "Report a vulnerability" button on this repository's Security tab. The report stays private between you and the maintainers, the whole exchange lives in one place, and it is the route that can end in a published advisory with a CVE and your name on it.
If you would rather not use GitHub, or the report does not fit that form, email contact@projectsend.org instead. Either is fine. What matters is that it does not start in public.
Please do not open a public issue for a security report. An issue is world-readable the moment it is filed, including by people running the version you just described how to break.
Enough to reproduce it, and nothing you would not want to write down:
You do not need a proof-of-concept exploit, and you should not run one against an installation that is not yours.
An acknowledgement within a few days, and a real answer — a fix, a plan, or a reason it is not what it looked like — once it has been reproduced. If a fix ships, you are credited by name unless you would rather not be.
This is a small project. If a week goes by in silence, assume the message went astray rather than that it was ignored, and send it again.
Anything that lets somebody reach a file, an account, or an installation they should not: the sharing and permission rules, authentication and two-factor, the public pages and share links, the API, the upload and download paths, and the setup and update flows.
Some things are worth a report but are not vulnerabilities in ProjectSend:
| ProjectSend 2.x | Supported. Fixes land on the current release line; upgrade before reporting that an older 2.x behaves differently. |
| The companion packages — community-modules, v1-migration-tool | Supported, on their own version lines. Report them here or on their own repository; both reach the same people. |
| ProjectSend Legacy (v1) | A separate application in a separate repository — see projectsend/legacy for how it handles reports. Nothing here applies to it. |
If you are trying to configure an installation rather than report a bug, the deployment documentation is what you want: INSTALL.md for a manual install, including the web server rules that keep uploaded files private, and DOCKER.md for the image, where those rules are already in place.
Two things are worth knowing whichever way you installed:
| Back | FazBrowse Home | New Git URL |