If you discover a security vulnerability in 1300.io, please report it responsibly. Do not open a public GitHub issue for security vulnerabilities.
Use GitHub's private vulnerability reporting
when available, or email security@stoicera.com with the subject
"1300.io security report". Do not include credentials, production data,
or unrelated personal information in the report.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
- Acknowledgment: Within 48 hours of receiving your report
- Initial assessment: Within 5 business days
- Resolution target: Within 30 days for critical issues, 90 days for lower severity
The following are in scope:
- Authentication and authorization bypasses
- Injection vulnerabilities (SQL, XSS, command injection)
- Sensitive data exposure
- Server-side request forgery (SSRF)
- Insecure file upload handling
- PDF generation security issues
The following are out of scope:
- Denial of service attacks
- Social engineering
- Known third-party issues without a project-specific impact or reproducible exploit
- Issues that require physical access to the server
| Version | Supported |
|---|---|
Latest on main |
Yes |
| Older releases | Best effort |
We follow responsible disclosure. Once a fix is released, we will:
- Credit the reporter (unless they prefer anonymity)
- Publish a security advisory on GitHub
- Update the changelog
We ask that you give us reasonable time to address the issue before public disclosure.