Skip to content

Security: IntersectMBO/mithril

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report (suspected) security vulnerabilities using the security advisory form on GitHub to draft a new Security advisory, or by email to security@intersectmbo.org. You will receive a response from us within 48 hours. If the issue is confirmed, we will release a patch as soon as possible.

Please provide a clear and concise description of the vulnerability, including:

  • the affected version(s) of Mithril,
  • steps that can be followed to exercise the vulnerability,
  • any workarounds or mitigations.

If you have developed any code or utilities that can help demonstrate the suspected vulnerability, please mention them in your report but DO NOT attempt to include them as attachments as this may cause your email to be blocked by spam filters.

Responsible Disclosure

We kindly request that reporters do not disclose the vulnerability publicly and do not exploit it, and that they allow us a reasonable amount of time to investigate and address it before publicly disclosing any details. We will not pursue legal action against individuals who report security vulnerabilities to us.

Security Policy

See the current version of the security policy in the Open-Source-Office repository.

Learn more about advisories related to IntersectMBO/mithril in the GitHub Advisory Database