AssetLane is built by Miriyam Core. This policy describes how to report security issues and what falls within scope.
Reports are welcome for vulnerabilities affecting:
- Authentication and session handling
- Admin authorization boundaries
- Stripe checkout and webhook verification
- bKash payment callback handling
- Secure download token generation and enforcement
- File upload validation and private storage access
- Secret and credential handling (environment variables, admin settings)
- SMTP configuration and email content injection
The following are generally not treated as security vulnerabilities:
- Missing features or configuration recommendations documented in BETA_LAUNCH.md
- Issues requiring physical or local machine access to an already-compromised host
- Social engineering attacks against merchants or buyers
- Denial of service through resource exhaustion without a practical exploit path
Do not open a public GitHub issue for security vulnerabilities.
Send a private report including:
- Summary of the issue
- Affected component or endpoint
- Steps to reproduce
- Potential impact
- Proof of concept, if available
If a dedicated security contact email is published for Miriyam Core, use that address. Until then, use the private contact method listed on the repository profile.
- Acknowledge receipt of the report
- Reproduce and assess severity
- Develop a fix or mitigation
- Coordinate disclosure with the reporter
We ask that you do not publicly disclose the issue until we have had reasonable time to address it.
Security fixes are applied to the active development branch. Self-hosted deployments should track the latest release and apply updates promptly.
Operators are responsible for:
- Setting a strong
JWT_SECRETin production - Serving the application over HTTPS
- Protecting database and storage volumes
- Rotating payment and SMTP credentials when compromised
See BETA_LAUNCH.md for deployment hardening guidance.