Skip to content

Security: Artaeon/1300io

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in 1300.io, please report it responsibly. Do not open a public GitHub issue for security vulnerabilities.

Use GitHub's private vulnerability reporting when available, or email security@stoicera.com with the subject "1300.io security report". Do not include credentials, production data, or unrelated personal information in the report.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if you have one)

Response Timeline

  • Acknowledgment: Within 48 hours of receiving your report
  • Initial assessment: Within 5 business days
  • Resolution target: Within 30 days for critical issues, 90 days for lower severity

Scope

The following are in scope:

  • Authentication and authorization bypasses
  • Injection vulnerabilities (SQL, XSS, command injection)
  • Sensitive data exposure
  • Server-side request forgery (SSRF)
  • Insecure file upload handling
  • PDF generation security issues

The following are out of scope:

  • Denial of service attacks
  • Social engineering
  • Known third-party issues without a project-specific impact or reproducible exploit
  • Issues that require physical access to the server

Supported Versions

Version Supported
Latest on main Yes
Older releases Best effort

Disclosure Policy

We follow responsible disclosure. Once a fix is released, we will:

  1. Credit the reporter (unless they prefer anonymity)
  2. Publish a security advisory on GitHub
  3. Update the changelog

We ask that you give us reasonable time to address the issue before public disclosure.

There aren't any published security advisories